Impact
The vulnerability is caused by improper null value handling during JSON parsing of the LoginPacket, which can cause the PocketMine-MP server to crash when receiving malformed JSON with unexpected null elements, resulting in denial of service.
Affected Systems
PocketMine-MP versions prior to 5.3.1 and 4.23.1 are affected.
Risk and Exploitability
The CVSS score of 8.7 indicates high severity. The EPSS score is not available, so exact exploitation probability is unknown. The vulnerability is not listed in CISA KEV. Based on the description, it is inferred that attackers can remotely send crafted LoginPacket messages with null elements to the server’s authentication endpoint to provoke a crash.
OpenCVE Enrichment