Input Validation Flaw in PocketMine-MP Affects Game Server Stability
CVE-2022-51018

7.1HIGH

Key Information:

Vendor

Pmmp

Vendor
CVE Published:
7 September 2026

What is CVE-2022-51018?

PocketMine-MP versions prior to 3.26.5 and 4.0.x prior to 4.0.5 are susceptible to an input validation vulnerability that fails to restrict the length of book page text, page count, and author/title length. This allows players with writable books to create excessively large NBT ('book bombs'), leading to increased bandwidth consumption and potential server crashes. Specifically, this flaw can cause the server to exceed the 1 MB chunk size limit when saving region-based worlds in PM3, or surpass the 32 KiB TAG_String limit in PM4, resulting in severe operational disruptions.

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.