Denial of Service Vulnerability in PocketMine-MP by PMMP
CVE-2026-86198

2.3LOW

Key Information:

Vendor

Pmmp

Vendor
CVE Published:
9 September 2026

What is CVE-2026-86198?

Versions of PocketMine-MP prior to 5.44.2 exhibit a vulnerability in resource pack handling, failing to adequately validate multiple packets with STATUS_COMPLETED status. This oversight allows malicious clients to inundate the system with crafted packets, triggering repeated pre-spawn progression. The exploitation of this vulnerability results in the creation of duplicate Player objects, significantly increasing memory consumption and generating excessive network traffic, potentially leading to service disruption.

Affected Version(s)

PocketMine-MP 0 < 5.44.2

PocketMine-MP 5.44.2

References

CVSS V4

Score:
2.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Genesizs
dktapps
.