Impact
The vulnerability allows attackers to cause a PocketMine-MP server to crash by sending item IDs that fall outside the valid range within item stack NBT data. Because the server does not validate these IDs, an uncaught exception is thrown during item stack creation, resulting in a denial of service for all connected players. The weakness can be classified as an input validation failure.
Affected Systems
All PocketMine-MP releases from the pmmp vendor prior to version 4.4.2 are affected. Any server running these older versions without updating is vulnerable.
Risk and Exploitability
The CVSS score of 7.1 indicates a medium severity level. No EPSS score is available and the vulnerability is not listed in the CISA KEV catalog, implying that there is no current evidence of exploitation. The attack can be performed remotely by a client that sends malformed item stack data, so the potential impact is a forced server crash that causes a service outage until the server is restarted.
OpenCVE Enrichment