CVE-2026-86202

Summary

PocketMine-MP versions before 5.39.2 contain a network amplification vulnerability in ActorEventPacket handling that allows clients to trigger consuming animations for all visible players. Attackers can send crafted ActorEventPacket messages to spam animation events to other clients and waste server CPU and memory resources.

Affected Software

VendorProductVersion RangeStatus
pmmpPocketMine-MP0 < 5.39.2affected
pmmpPocketMine-MP5.39.2unaffected

Weaknesses

  • CWE-406: Insufficient Control of Network Message Volume (Network Amplification)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References