Entity Despawn Vulnerability in PocketMine-MP by PocketMine
CVE-2026-86203
6.3MEDIUM
What is CVE-2026-86203?
PocketMine-MP versions prior to 5.39.2 are susceptible to a flaw that fails to properly validate the despawn state of entities when processing attack packets received from clients. This oversight allows attackers to exploit a race condition by targeting players who are disconnecting. As a result, multiple death handlers can be triggered, leading to repeated drops of inventory items and experience, enabling item duplication. Users are advised to upgrade to version 5.39.2 or higher to mitigate this vulnerability.
Affected Version(s)
PocketMine-MP 0 < 5.39.2
PocketMine-MP 5.39.2
