CVE-2022-51012
largeDenial-of-Service Flaw in PocketMine-MP via Malformed NBT Packets
PocketMine-MP, a widely used open-source server implementation for Minecraft: Bedrock Edition, fails to properly validate NBT data types when deserializing inventory transaction packets sent by clients. A player with an account on the server (low privileges, no user interaction required) can send a crafted inventory transaction containing malformed NBT tags, causing the server process to crash. The attacker gains denial of service only, with no confidentiality or integrity impact per the CVSS scoring, but a single malicious client can repeatedly crash the affected server. Any operator running PocketMine-MP before version 4.2.9 is affected, with public servers that accept arbitrary players most exposed. No public proof-of-concept is known, the issue is not in CISA's KEV catalog, and EPSS estimates only a 0.5% probability of exploitation in the next 30 days.
What to do: Upgrade PocketMine-MP to version 4.2.9 or later. Until patched, restrict access to trusted players (e.g., via whitelisting), since any authenticated client can crash the server, and monitor public servers for unexplained crashes or restarts. No public exploit is known and EPSS is low, but internet-facing servers should patch promptly because the attack requires only a logged-in player.
| PocketMine-MP Project (open source) PocketMine-MP | All versions prior to 4.2.9 (fixed in 4.2.9) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
PocketMine-MP versions before 4.2.9 fail to properly validate NBT data types during deserialization of inventory transaction packets from clients. Attackers can send crafted inventory transactions with malformed NBT tags to trigger server crashes and cause denial of service.
- Weakness
- CWE-20
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.