Security Advisory

CVE-2020-37277

CVSS 6.5
MEDIUM

Vulnerability Description

PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send specially crafted InventoryTransactionPackets with multiple conflicting pathways to cause exponential processing complexity, freezing the server.
Published Date 2026-09-06T12:17:13.547
Data Feed NIST National Vulnerability Database