High severity7.5NVD Advisory· Published Sep 9, 2026· Updated Sep 9, 2026
CVE-2023-54390
CVE-2023-54390
Description
PocketMine-MP versions before 5.3.1 and 4.23.1 contain a denial of service vulnerability in LoginPacket JSON parsing due to improper null value handling in arrays. Attackers can send malformed JSON with unexpected null elements in LoginPacket to crash the server.
Affected products
2<5.3.1, <4.23.1+ 1 more
- (no CPE)range: <5.3.1, <4.23.1
- (no CPE)
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.