Low severity3.7NVD Advisory· Published Sep 9, 2026
CVE-2026-86203
CVE-2026-86203
Description
PocketMine-MP versions before 5.39.2 fail to validate entity despawn state when processing attack packets from clients. Attackers can exploit a race condition by attacking a disconnecting player to trigger multiple death handlers, causing inventory items and experience to drop multiple times for duplication.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: <5.39.2
Patches
Vulnerability mechanics
References
3News mentions
0No linked articles in our index yet.