Security Advisory

CVE-2022-51017

CVSS 7.5
HIGH

Vulnerability Description

PocketMine-MP versions before 3.26.5 and 4.0.5 fail to validate the length of skin data fields submitted by players, allowing uncapped values to exceed the 32767 byte TAG_String limit. Attackers can submit oversized skin data fields like skinID or geometryName to trigger exceptions during NBT data serialization, causing server crashes.
Published Date 2026-09-07T13:17:23.747
Data Feed NIST National Vulnerability Database