PocketMine-MP before 4.2.10 fails to validate the total length of incoming chat message blobs before splitting them by newline characters, allowing attackers to send large messages containing many newlines. Malicious clients can send megabyte-sized chat packets and bombard the server with thousands of such messages, causing server lockups lasting seconds or minutes.
Metrics
Affected Vendors & Products
References
History
Mon, 07 Sep 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pmmp
Pmmp pocketmine-mp |
|
| Vendors & Products |
Pmmp
Pmmp pocketmine-mp |
Mon, 07 Sep 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PocketMine-MP before 4.2.10 fails to validate the total length of incoming chat message blobs before splitting them by newline characters, allowing attackers to send large messages containing many newlines. Malicious clients can send megabyte-sized chat packets and bombard the server with thousands of such messages, causing server lockups lasting seconds or minutes. | |
| Title | PocketMine-MP before 4.2.10 Denial of Service via Chat Messages | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-07T12:55:05.898Z
Updated: 2026-09-07T12:55:05.898Z
Reserved: 2026-09-05T21:01:56.324Z
Link: CVE-2022-51011
No data.
Status : Deferred
Published: 2026-09-07T13:17:22.890
Modified: 2026-09-08T19:59:42.500
Link: CVE-2022-51011
No data.