PT-2026-86516 · Unknown · Pocketmine-Mp
CVSS v4.0
6.9
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
PocketMine-MP versions prior to 4.12.3
Description
The software fails to limit unauthenticated sessions, which allows attackers to exhaust available player slots. This occurs when sessions are created without sending a
LoginPacket, enabling a flood of unauthenticated connections that occupy the maximum player capacity and prevent legitimate players from joining the server.Recommendations
Update to version 4.12.3 or later.
Exploit
Fix
DoS
Allocation of Resources Without Limits
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Pocketmine-Mp