{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/pocketmine-mp--4.0.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:pocketmine:pocketmine_mp:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2022-51017"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["PocketMine-MP (\u003c 3.26.5)","PocketMine-MP (\u003c 4.0.5)"],"_cs_severities":["low"],"_cs_tags":["denial-of-service","vulnerability"],"_cs_type":"advisory","_cs_vendors":["PocketMine"],"content_html":"\u003cp\u003ePocketMine-MP versions before 3.26.5 and 4.0.5 contain a vulnerability arising from improper input validation regarding the length of skin data fields provided by game clients during the connection process. An attacker can manipulate fields such as skinID or geometryName to exceed the 32767 byte TAG_String limit imposed by the NBT protocol used by the server. When the server attempts to process or serialize this maliciously oversized data, it triggers internal exceptions within the NBT handling logic. If not properly caught or sanitized, these exceptions result in a process crash, effectively rendering the game server unavailable to legitimate players. This vulnerability represents a significant risk to service availability for server administrators operating impacted versions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in a persistent denial-of-service condition for the targeted PocketMine-MP game server. This disrupts gameplay for all connected users and requires manual administrative intervention to restore service availability. Organizations hosting competitive or public-facing game environments are at the highest risk of repeated service interruptions.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of PocketMine-MP to version 3.26.5 or 4.0.5 or later to resolve the underlying input validation flaw.\u003c/li\u003e\n\u003cli\u003eMonitor server logs for repeated application-layer crashes or stack trace exceptions involving NBT serialization modules to identify potential exploitation attempts.\u003c/li\u003e\n\u003cli\u003eImplement rate limiting or packet size inspection at the network edge, if possible, to drop incoming game packets that exceed the expected size for skin-related data payloads.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-07T13:36:13Z","date_published":"2026-09-07T13:36:13Z","id":"https://feed.craftedsignal.io/briefs/2026-09-pocketmine-dos/","summary":"PocketMine-MP versions prior to 3.26.5 and 4.0.5 are vulnerable to a denial-of-service attack due to insufficient validation of player-submitted skin data lengths.","title":"Denial of Service Vulnerability in PocketMine-MP","url":"https://feed.craftedsignal.io/briefs/2026-09-pocketmine-dos/"}],"language":"en","title":"CraftedSignal Threat Feed - PocketMine-MP (\u003c 4.0.5)","version":"https://jsonfeed.org/version/1.1"}