CVE-2026-86203

Summary

PocketMine-MP versions before 5.39.2 fail to validate entity despawn state when processing attack packets from clients. Attackers can exploit a race condition by attacking a disconnecting player to trigger multiple death handlers, causing inventory items and experience to drop multiple times for duplication.

Affected Software

VendorProductVersion RangeStatus
pmmpPocketMine-MP0 < 5.39.2affected
pmmpPocketMine-MP5.39.2unaffected

Weaknesses

  • CWE-664: Improper Control of a Resource Through its Lifetime

References