High severity7.5NVD Advisory· Published Sep 9, 2026
CVE-2023-54393
CVE-2023-54393
Description
PocketMine-MP versions before 4.20.5 contain a denial of service vulnerability in LoginPacket JSON parsing due to improper validation in the JsonMapper dependency. Attackers can send malformed JSON structures in LoginPacket to crash the server.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: <4.20.5
Patches
Vulnerability mechanics
References
4- github.com/pmmp/PocketMine-MP/commit/09668a37d66c6023685a948b7550c918620e98f2nvd
- github.com/pmmp/PocketMine-MP/commit/a31902a31f5b6fdb832f57c0e3a3f16a3b41c012nvd
- github.com/pmmp/PocketMine-MP/security/advisories/GHSA-pqp3-8rrw-g8vmnvd
- www.vulncheck.com/advisories/pocketmine-mp-before-4.20.5-denial-of-service-via-loginpacketnvd
News mentions
0No linked articles in our index yet.