PocketMine-MP before 5.11.1 Denial of Service via LoginPacket
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.7epss 0.4%
exploitation probability
0.4%top 64% of all CVEs
observed exploitation
nono source reports it
PocketMine-MP before 5.11.1 contains a denial of service vulnerability in LoginPacket JSON processing that allows remote attackers to crash the server by sending malformed JSON data. Attackers can exploit improper object initialization from scalar JSON types to trigger unset required properties, causing the application to crash.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Affected products
pmmp · PocketMine-MPReferences
https://github.com/pmmp/PocketMine-MP/commit/6872661fd03649cc7a8762c41c16e9ee5a4de1c9https://github.com/pmmp/PocketMine-MP/commit/b96a209f9e8b76b899a0d0918493cd87eb3c02a7https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-h6j3-j35f-v2x7https://www.vulncheck.com/advisories/pocketmine-mp-before-5.11.1-denial-of-service-via-loginpacket