Impact
PocketMine-MP implementations between version 4.20.0 and before 4.22.3 (and the 5.x branch before 5.2.1) do not validate NBT tag types included in a BlockActorDataPacket, allowing a malicious client to send a packet with sign NBT data that contains an unexpected tag type. The resulting UnexpectedTagTypeException is unhandled, causing the server process to terminate and prevent any further processing of incoming connections. This flaw leads to a loss of availability for all connected players without compromising confidentiality or integrity.
Affected Systems
The affected product is PocketMine-MP, an open‑source Bedrock edition Minecraft server. Servers running any release from 4.20.0 up to, but not including, 4.22.3 are vulnerable, as are all 5.x releases before 5.2.1. Users operating those versions are at risk of being tricked into a server crash by a malicious client.
Risk and Exploitability
The vulnerability scores a CVSS of 7.1, reflecting a high impact denial‑of‑service risk. The attack vector is inferred to be remote, requiring an attacker to establish a client connection to the server and send a specially crafted BlockActorDataPacket. No EPSS score is provided in this report, and the flaw is not listed in the CISA KEV catalog. An exploitation that succeeds will terminate the server process, forcing a restart and disrupting service for all players.
OpenCVE Enrichment