Impact
PocketMine‑MP before version 5.11.1 contains a deserialization weakness in the LoginPacket JSON handler. An attacker can send malformed JSON data that causes improper object initialization and unset required properties, which in turn crashes the server. The flaw falls under the deserialization of untrusted data category.
Affected Systems
PocketMine‑MP servers running any version earlier than 5.11.1 are potentially impacted. Operators of community or private Minecraft PE servers using this software face the risk unless the server is updated.
Risk and Exploitability
The vulnerability has a CVSS score of 8.7, indicating high severity. The EPSS score is not available and it is not listed in the CISA KEV catalog. The likely attack vector is remote network traffic to the LoginPacket endpoint; an attacker only needs the ability to send packets on the server’s login port and does not require authentication or elevated privileges.
OpenCVE Enrichment