CVE-2026-86204
7.1
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
Summary
PocketMine-MP versions before 5.39.2 fail to limit JSON payload size in ModalFormResponsePacket handling, allowing authenticated players to cause denial of service. Attackers can send modal form response packets with massive JSON arrays to exhaust server memory and CPU resources, rendering the server unresponsive.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| pmmp | PocketMine-MP | 0 < 5.39.2 | affected |
| pmmp | PocketMine-MP | 5.39.2 | unaffected |
Weaknesses
- CWE-400: Uncontrolled Resource Consumption
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: no
- Technical Impact: partial
Additional References
References
- https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-788v-5pfp-93ff
- https://www.vulncheck.com/advisories/pocketmine-mp-before-5.39.2-denial-of-service-via-modalformresponsepacket
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.