CVE-2026-86202 PUBLISHED

PocketMine-MP before 5.39.2 Network Amplification via ActorEventPacket

Assigner: VulnCheck
Reserved: 05.09.2026 Published: 09.09.2026 Updated: 09.09.2026

PocketMine-MP versions before 5.39.2 contain a network amplification vulnerability in ActorEventPacket handling that allows clients to trigger consuming animations for all visible players. Attackers can send crafted ActorEventPacket messages to spam animation events to other clients and waste server CPU and memory resources.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 5.3

Product Status

Vendor pmmp
Product PocketMine-MP
Versions Default: unaffected
  • affected from 0 to 5.39.2 (excl.)
  • Version 5.39.2 is unaffected

Credits

  • dktapps finder

References

Problem Types

  • Insufficient Control of Network Message Volume (Network Amplification) CWE