PocketMine-MP vulnerability

PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send specially crafted InventoryTransactionPackets with multiple conflicting pathways to cause exponential processing complexity, freezing the server.

Published 6 Sep 2026Updated 6 Sep 20263 sources
CVSS 7.1

Record history

Record created from the first normalized source observation.
Metadata and source references refreshed.