VYPR
Medium severity6.5NVD Advisory· Published Sep 9, 2026

CVE-2023-54392

CVE-2023-54392

Description

PocketMine-MP versions >= 4.20.0 before 4.22.3 (and before 5.2.1 in the 5.x branch) fail to validate NBT tag types in BlockActorDataPacket. A player can crash the server by sending a packet containing sign NBT data with an incorrect tag type, triggering an unhandled UnexpectedTagTypeException that terminates the server process.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • Pmmp/Pocketmine Mpreferences2 versions
    (expand)+ 1 more
    • (no CPE)
    • (no CPE)range: >= 4.20.0, < 4.22.3 and < 5.2.1

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.