Impact
PocketMine-MP versions older than 5.42.1 include a denial‑of‑service flaw in the LoginPacket handler. By encoding a large number of unknown properties into the clientData JSON Web Token, an attacker can send malicious login packets that cause the server to spend excessive CPU time parsing and discarding these properties, thereby degrading overall server performance.
Affected Systems
All PocketMine-MP installations running a version before 5.42.1 are vulnerable. This includes any community or private server that has not applied the 5.42.1 update. No specific minimum version beyond "<5.42.1" is listed, so any release preceding 5.42.1 is considered at risk.
Risk and Exploitability
Attackers can remotely exploit the flaw by crafting login packets with a high number of unknown clientData properties, a method that requires no authentication and can be performed from any IP address. The CVSS score of 6.9 indicates moderate severity; the EPSS score is not available, and the vulnerability has not been listed in CISA’s KEV catalog. Despite the moderate score, the attack is straightforward and could be automated, making it a realistic threat for servers that are publicly accessible.
OpenCVE Enrichment