PocketMine-MP before 5.11.1 contains a denial of service vulnerability in LoginPacket JSON processing that allows remote attackers to crash the server by sending malformed JSON data. Attackers can exploit improper object initialization from scalar JSON types to trigger unset required properties, causing the application to crash.
Metrics
Affected Vendors & Products
References
History
Thu, 10 Sep 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Pmmp
Pmmp pocketmine-mp |
|
| Vendors & Products |
Pmmp
Pmmp pocketmine-mp |
Wed, 09 Sep 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PocketMine-MP before 5.11.1 contains a denial of service vulnerability in LoginPacket JSON processing that allows remote attackers to crash the server by sending malformed JSON data. Attackers can exploit improper object initialization from scalar JSON types to trigger unset required properties, causing the application to crash. | |
| Title | PocketMine-MP before 5.11.1 Denial of Service via LoginPacket | |
| Weaknesses | CWE-502 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published: 2026-09-09T13:31:55.512Z
Updated: 2026-09-09T13:31:55.512Z
Reserved: 2026-08-16T13:02:14.690Z
Link: CVE-2024-58381
No data.
Status : Deferred
Published: 2026-09-09T14:17:10.187
Modified: 2026-09-09T20:20:21.673
Link: CVE-2024-58381
No data.