CVE-2023-54396 PUBLISHED

PocketMine-MP before 4.8.1 Server Crash via Banner NBT

Assigner: VulnCheck
Reserved: 05.09.2026 Published: 09.09.2026 Updated: 09.09.2026

PocketMine-MP versions before 4.8.1 fail to validate dye color IDs in banner NBT data during deserialization. Attackers can provide invalid color values in inventory transactions or via commands to trigger undefined offset errors and crash the server.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor pmmp
Product PocketMine-MP
Versions Default: unaffected
  • affected from 0 to 4.8.1 (excl.)
  • Version 4.8.1 is unaffected

References

Problem Types

  • Improper Validation of Array Index CWE