Impact
This vulnerability allows attackers to send specially crafted LoginPackets with large or deeply nested JWT clientData structures, causing the server to perform extensive logging without sanitization. The resulting out‑of‑memory condition crashes the PocketMine‑MP server, leading to a denial of service. The weakness is a classic case of uncontrolled resource consumption (CWE‑400).
Affected Systems
PocketMine‑MP server software. Versions prior to 5.41.1 are affected. The flaw exists in the LoginPacket handler used by all deployments of PocketMine‑MP that accept client connections.
Risk and Exploitability
The CVSS score of 8.7 indicates a high severity, while the EPSS score is not available, meaning recent evidence of exploitation is not reported. The vulnerability is not listed in CISA KEV, but the attack vector requires a remote client to connect to the server and send a malicious LoginPacket. No authentication is needed, making it trivial for an attacker to trigger the crash. Administrators should be aware that a single malicious packet can bring the server down, especially in high‑traffic environments.
OpenCVE Enrichment