Denial of Service Vulnerability in PocketMine-MP by PocketMine
CVE-2026-86204
7.1HIGH
What is CVE-2026-86204?
PocketMine-MP versions earlier than 5.39.2 are vulnerable to denial of service attacks due to inadequate restrictions on JSON payload sizes in ModalFormResponsePacket processing. Authenticated users can exploit this flaw by sending excessively large JSON arrays as modal form responses, which can deplete server memory and CPU resources. This can result in the server becoming unresponsive, severely affecting gameplay and server performance.
Affected Version(s)
PocketMine-MP 0 < 5.39.2
PocketMine-MP 5.39.2
