CVE-2026-86200 PUBLISHED

PocketMine-MP before 5.42.1 LogDoS via LoginPacket clientData JWT

Assigner: VulnCheck
Reserved: 05.09.2026 Published: 09.09.2026 Updated: 09.09.2026

PocketMine-MP versions before 5.42.1 contain a denial of service vulnerability in the LoginPacket handler that allows remote attackers to flood warning messages by injecting numerous junk properties into the clientData JWT. Attackers can craft malicious login packets with excessive unknown properties to waste server CPU time and degrade performance.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor pmmp
Product PocketMine-MP
Versions Default: unaffected
  • affected from 0 to 5.42.1 (excl.)
  • Version 5.42.1 is unaffected

Credits

  • iYozemMc reporter
  • dktapps finder

References

Problem Types

  • Logging of Excessive Data CWE