CVE-2023-54394 PUBLISHED

PocketMine-MP before 4.18.0-ALPHA2 Bandwidth Amplification via InventoryTransactionPacket

Assigner: VulnCheck
Reserved: 05.09.2026 Published: 09.09.2026 Updated: 09.09.2026

PocketMine-MP before 4.18.0-ALPHA2 fails to rate-limit mismatch type InventoryTransactionPacket requests, allowing attackers to trigger excessive inventory synchronization. Attackers can send numerous mismatch transactions to force the server to transmit large amounts of serialized inventory data, consuming significant bandwidth without authentication.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor pmmp
Product PocketMine-MP
Versions Default: unaffected
  • affected from 0 to 4.18.0-ALPHA2 (excl.)
  • Version 4.18.0-ALPHA2 is unaffected

Credits

  • dktapps finder

References

Problem Types

  • Allocation of Resources Without Limits or Throttling CWE