Impact
PocketMine-MP versions prior to 4.7.2 incorrectly process exceptions from the adhocore/json-comment library when parsing skin geometry JSON during login or skin updates. An attacker can send malformed geometry data in a login or skin packet, causing an unhandled RuntimeException that crashes the server, resulting in a denial of service.
Affected Systems
The vulnerability affects the PocketMine-MP server software from the pmmp vendor. All installations running a version earlier than 4.7.2 are vulnerable.
Risk and Exploitability
The flaw carries a CVSS score of 8.7, indicating high severity. No EPSS score is available, but because it exploits a server crash via a simple packet injection, the likelihood of exploitation in the wild is considered moderate to high. The vulnerability is not listed in the CISA KEV catalog. Attackers can achieve a remote denial of service by connecting to the server and sending a packet that contains invalid geometry JSON, triggering the crash.
OpenCVE Enrichment