CVE-2026-86204 PUBLISHED

PocketMine-MP before 5.39.2 Denial of Service via ModalFormResponsePacket

Assigner: VulnCheck
Reserved: 05.09.2026 Published: 09.09.2026 Updated: 09.09.2026

PocketMine-MP versions before 5.39.2 fail to limit JSON payload size in ModalFormResponsePacket handling, allowing authenticated players to cause denial of service. Attackers can send modal form response packets with massive JSON arrays to exhaust server memory and CPU resources, rendering the server unresponsive.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS Score: 7.1

Product Status

Vendor pmmp
Product PocketMine-MP
Versions Default: unaffected
  • affected from 0 to 5.39.2 (excl.)
  • Version 5.39.2 is unaffected

Credits

  • Zwuiix-cmd reporter
  • dktapps finder

References

Problem Types

  • Uncontrolled Resource Consumption CWE