Input Validation Flaw in PocketMine-MP Affects Game Server Stability
CVE-2022-51018
7.1HIGH
What is CVE-2022-51018?
PocketMine-MP versions prior to 3.26.5 and 4.0.x prior to 4.0.5 are susceptible to an input validation vulnerability that fails to restrict the length of book page text, page count, and author/title length. This allows players with writable books to create excessively large NBT ('book bombs'), leading to increased bandwidth consumption and potential server crashes. Specifically, this flaw can cause the server to exceed the 1 MB chunk size limit when saving region-based worlds in PM3, or surpass the 32 KiB TAG_String limit in PM4, resulting in severe operational disruptions.
