Security Advisory

CVE-2022-51009

CVSS 7.5
HIGH

Vulnerability Description

PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin packets with invalid geometry JSON to trigger an unhandled RuntimeException, causing server crash.
Published Date 2026-09-06T12:17:15.073
Data Feed NIST National Vulnerability Database