PocketMine-MP 5.39.2 之前的版本在处理来自客户端的攻击数据包时,未能正确验证实体的消失(despawn)状态。攻击者可以利用这一竞争条件,对正在断开的玩家发起攻击,从而触发多个死亡处理程序,导致物品和经验值多次掉落,进而实现物品或经验的复制(duplication)。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| pmmp | PocketMine-MP | 0 ~ 5.39.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2024-58381 | 7.5 HIGH | PocketMine-MP before 5.11.1 Denial of Service via LoginPacket |
| CVE-2026-86199 | 7.5 HIGH | PocketMine-MP before 5.43.1 Denial of Service via unauthenticated login |
| CVE-2026-86201 | 7.5 HIGH | PocketMine-MP before 5.41.1 LogDoS via LoginPacket clientData |
| CVE-2023-54390 | 7.5 HIGH | PocketMine-MP before 5.3.1 Denial of Service via LoginPacket |
| CVE-2023-54393 | 7.5 HIGH | PocketMine-MP before 4.20.5 Denial of Service via LoginPacket |
| CVE-2023-54355 | 7.5 HIGH | PocketMine-MP 5.2.0 Server Crash via Incorrect EC Curve |
| CVE-2023-54396 | 6.5 MEDIUM | PocketMine-MP before 4.8.1 Server Crash via Banner NBT |
| CVE-2023-54392 | 6.5 MEDIUM | PocketMine-MP before 4.22.3 Denial of Service via BlockActorDataPacket |
| CVE-2024-58380 | 6.5 MEDIUM | PocketMine-MP before 5.11.2 Denial of Service via BookEditPacket |
| CVE-2025-71417 | 6.5 MEDIUM | PocketMine-MP before 5.32.1 Denial of Service via ResourcePackClientResponsePacket |
| CVE-2026-86204 | 6.5 MEDIUM | PocketMine-MP before 5.39.2 Denial of Service via ModalFormResponsePacket |
| CVE-2025-71418 | 5.3 MEDIUM | PocketMine-MP before 5.25.2 Denial of Service via explode |
| CVE-2026-86200 | 5.3 MEDIUM | PocketMine-MP before 5.42.1 LogDoS via LoginPacket clientData JWT |
| CVE-2023-54395 | 4.3 MEDIUM | PocketMine-MP before 4.12.5 Denial of Service via ModalFormResponsePacket |
| CVE-2023-54394 | 4.3 MEDIUM | PocketMine-MP before 4.18.0-ALPHA2 Bandwidth Amplification via InventoryTransactionPacket |
| CVE-2026-86202 | 4.3 MEDIUM | PocketMine-MP before 5.39.2 Network Amplification via ActorEventPacket |
| CVE-2026-86198 | 4.2 MEDIUM | PocketMine-MP before 5.44.2 Denial of Service via ResourcePackClientResponsePacket |
No comments yet