VYPR
High severity7.5NVD Advisory· Published Sep 9, 2026· Updated Sep 9, 2026

CVE-2023-54390

CVE-2023-54390

Description

PocketMine-MP versions before 5.3.1 and 4.23.1 contain a denial of service vulnerability in LoginPacket JSON parsing due to improper null value handling in arrays. Attackers can send malformed JSON with unexpected null elements in LoginPacket to crash the server.

Affected products

2
  • Pmmp/Pocketmine Mpllm-fuzzy2 versions
    <5.3.1, <4.23.1+ 1 more
    • (no CPE)range: <5.3.1, <4.23.1
    • (no CPE)

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.