Denial of Service Vulnerability in PocketMine-MP by PocketMine
CVE-2026-86200
6.9MEDIUM
What is CVE-2026-86200?
PocketMine-MP prior to version 5.42.1 is exposed to a denial of service vulnerability through its LoginPacket handler. This issue enables remote attackers to disrupt server activities by flooding it with excessive warning messages, which are created by injecting numerous malicious properties into the clientData JWT. By crafting these malicious login packets, attackers can significantly degrade server performance by wasting CPU resources, leading to severe service interruptions. Timely patching is crucial to securing affected servers.
Affected Version(s)
PocketMine-MP 0 < 5.42.1
PocketMine-MP 5.42.1
