Impact
The vulnerability exists in PocketMine‑MP servers less than version 3.18.1. The server does not validate NaN or INF values sent in the position and rotation fields of a MovePlayerPacket. A malicious attacker can craft a packet that contains these invalid floating‑point values. When the server processes the packet, unhandled mathematical operations result in a crash, causing a denial of service. Clients may also fail to render other players correctly, disrupting normal gameplay.
Affected Systems
PocketMine‑MP, all releases prior to 3.18.1, including 3.18.0 and earlier. The issue is specific to the MovePlayerPacket handling in these server versions. Any server running these versions that accepts connections from client devices is affected.
Risk and Exploitability
The CVSS score of 7.1 indicates moderate to high severity. No EPSS score is available, so the quantified likelihood of exploitation is unknown; however, the vulnerability is remote and does not require authentication. Attackers can trigger the exploit from any client that can reach the server. The issue is not listed in the CISA KEV catalog, so no public exploit is confirmed yet, but the attack vector is straightforward. Given the lack of authentication requirements and the vulnerability’s impact, administrators should treat it as a high‑risk threat for exposed servers.
OpenCVE Enrichment