Impact
PocketMine-MP before version 5.39.2 does not limit the size of JSON payloads in ModalFormResponsePacket handling. An attacker who is authenticated can send a packet containing an extremely large JSON array, causing the server to allocate excessive memory and consume CPU resources before responding, which can render the server unresponsive.
Affected Systems
PocketMine-MP servers running any version older than 5.39.2 are affected. The vulnerability is tied to the pmmp:PocketMine-MP product line and applies to all deployments of those preceding releases.
Risk and Exploitability
The CVSS score of 7.1 indicates a high severity impact. EPSS information is not available and the vulnerability is not listed in CISA's KEV catalog, suggesting that it has not yet been widely exploited in the wild. Attackers must be able to authenticate to the server, after which they can send oversized modal form response packets. Successful exploitation results in a denial of service that can affect all players and disrupt server administration.
OpenCVE Enrichment