Denial of Service Vulnerability in PocketMine-MP by PocketMine
CVE-2026-86200

6.9MEDIUM

Key Information:

Vendor

Pmmp

Vendor
CVE Published:
9 September 2026

What is CVE-2026-86200?

PocketMine-MP prior to version 5.42.1 is exposed to a denial of service vulnerability through its LoginPacket handler. This issue enables remote attackers to disrupt server activities by flooding it with excessive warning messages, which are created by injecting numerous malicious properties into the clientData JWT. By crafting these malicious login packets, attackers can significantly degrade server performance by wasting CPU resources, leading to severe service interruptions. Timely patching is crucial to securing affected servers.

Affected Version(s)

PocketMine-MP 0 < 5.42.1

PocketMine-MP 5.42.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

iYozemMc
dktapps
.