Description
PocketMine-MP versions before 5.42.1 contain a denial of service vulnerability in the LoginPacket handler that allows remote attackers to flood warning messages by injecting numerous junk properties into the clientData JWT. Attackers can craft malicious login packets with excessive unknown properties to waste server CPU time and degrade performance.
Published: 2026-09-09
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service (CPU exhaustion, performance degradation)
Action: Patch Now
AI Analysis

Impact

PocketMine-MP versions older than 5.42.1 include a denial‑of‑service flaw in the LoginPacket handler. By encoding a large number of unknown properties into the clientData JSON Web Token, an attacker can send malicious login packets that cause the server to spend excessive CPU time parsing and discarding these properties, thereby degrading overall server performance.

Affected Systems

All PocketMine-MP installations running a version before 5.42.1 are vulnerable. This includes any community or private server that has not applied the 5.42.1 update. No specific minimum version beyond "<5.42.1" is listed, so any release preceding 5.42.1 is considered at risk.

Risk and Exploitability

Attackers can remotely exploit the flaw by crafting login packets with a high number of unknown clientData properties, a method that requires no authentication and can be performed from any IP address. The CVSS score of 6.9 indicates moderate severity; the EPSS score is not available, and the vulnerability has not been listed in CISA’s KEV catalog. Despite the moderate score, the attack is straightforward and could be automated, making it a realistic threat for servers that are publicly accessible.

Generated by OpenCVE AI on September 9, 2026 at 15:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade PocketMine-MP to version 5.42.1 or later.
  • If an immediate upgrade is not possible, apply network‑level rate limiting or firewall rules to restrict the rate of incoming login packets from untrusted IP addresses.
  • Regularly monitor server CPU usage and log files for unusually high numbers of warning messages or CPU spikes that may indicate an ongoing attack.

Generated by OpenCVE AI on September 9, 2026 at 15:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Pmmp
Pmmp pocketmine-mp
Vendors & Products Pmmp
Pmmp pocketmine-mp

Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description PocketMine-MP versions before 5.42.1 contain a denial of service vulnerability in the LoginPacket handler that allows remote attackers to flood warning messages by injecting numerous junk properties into the clientData JWT. Attackers can craft malicious login packets with excessive unknown properties to waste server CPU time and degrade performance.
Title PocketMine-MP before 5.42.1 LogDoS via LoginPacket clientData JWT
Weaknesses CWE-779
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Pmmp Pocketmine-mp
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-18T17:23:08.985Z

Reserved: 2026-09-05T11:52:36.821Z

Link: CVE-2026-86200

cve-icon Vulnrichment

Updated: 2026-09-18T17:17:43.635Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T14:17:21.123

Modified: 2026-09-18T18:17:18.523

Link: CVE-2026-86200

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T15:15:06Z

Weaknesses
  • CWE-779

    Logging of Excessive Data