Description
PocketMine-MP before 5.41.1 contains a denial of service vulnerability in LoginPacket processing where large or complex structures in unknown clientData JWT properties cause excessive logging without sanitization. Attackers can send crafted LoginPackets with deeply nested or massive object structures to trigger out-of-memory conditions and crash the server.
Published: 2026-09-09
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

This vulnerability allows attackers to send specially crafted LoginPackets with large or deeply nested JWT clientData structures, causing the server to perform extensive logging without sanitization. The resulting out‑of‑memory condition crashes the PocketMine‑MP server, leading to a denial of service. The weakness is a classic case of uncontrolled resource consumption (CWE‑400).

Affected Systems

PocketMine‑MP server software. Versions prior to 5.41.1 are affected. The flaw exists in the LoginPacket handler used by all deployments of PocketMine‑MP that accept client connections.

Risk and Exploitability

The CVSS score of 8.7 indicates a high severity, while the EPSS score is not available, meaning recent evidence of exploitation is not reported. The vulnerability is not listed in CISA KEV, but the attack vector requires a remote client to connect to the server and send a malicious LoginPacket. No authentication is needed, making it trivial for an attacker to trigger the crash. Administrators should be aware that a single malicious packet can bring the server down, especially in high‑traffic environments.

Generated by OpenCVE AI on September 9, 2026 at 15:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update PocketMine‑MP to version 5.41.1 or later to apply the patched LoginPacket handling.
  • If an upgrade is delayed, configure server settings or firewall rules to limit the size or frequency of LoginPackets to mitigate the resource exhaustion impact.
  • Monitor server logs and performance metrics for unexpected spikes or crashes, and consider temporarily disabling logging for clientData until the issue is resolved.

Generated by OpenCVE AI on September 9, 2026 at 15:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Pmmp
Pmmp pocketmine-mp
Vendors & Products Pmmp
Pmmp pocketmine-mp

Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description PocketMine-MP before 5.41.1 contains a denial of service vulnerability in LoginPacket processing where large or complex structures in unknown clientData JWT properties cause excessive logging without sanitization. Attackers can send crafted LoginPackets with deeply nested or massive object structures to trigger out-of-memory conditions and crash the server.
Title PocketMine-MP before 5.41.1 LogDoS via LoginPacket clientData
Weaknesses CWE-400
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Pmmp Pocketmine-mp
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-14T13:19:04.138Z

Reserved: 2026-09-05T11:52:36.821Z

Link: CVE-2026-86201

cve-icon Vulnrichment

Updated: 2026-09-14T13:18:58.456Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T14:17:21.263

Modified: 2026-09-14T14:17:15.437

Link: CVE-2026-86201

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T16:30:17Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption