PocketMine-MP versions before 4.2.9 fail to properly validate NBT data types during deserialization of inventory transaction packets from clients. Attackers can send crafted inventory transactions with malformed NBT tags to trigger server crashes and cause denial of service.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Mon, 07 Sep 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PocketMine-MP versions before 4.2.9 fail to properly validate NBT data types during deserialization of inventory transaction packets from clients. Attackers can send crafted inventory transactions with malformed NBT tags to trigger server crashes and cause denial of service. | |
| Title | PocketMine-MP before 4.2.9 Denial of Service via NBT Deserialization | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-07T12:55:06.530Z
Reserved: 2026-09-05T21:02:18.431Z
Link: CVE-2022-51012
No data.
Status : Received
Published: 2026-09-07T13:17:23.030
Modified: 2026-09-07T13:17:23.030
Link: CVE-2022-51012
No data.
OpenCVE Enrichment
No data.
Weaknesses