VYPR
Medium severity6.5NVD Advisory· Published Sep 9, 2026· Updated Sep 9, 2026

CVE-2026-86204

CVE-2026-86204

Description

PocketMine-MP versions before 5.39.2 fail to limit JSON payload size in ModalFormResponsePacket handling, allowing authenticated players to cause denial of service. Attackers can send modal form response packets with massive JSON arrays to exhaust server memory and CPU resources, rendering the server unresponsive.

Affected products

2
  • Pmmp/Pocketmine Mpllm-fuzzy2 versions
    <5.39.2+ 1 more
    • (no CPE)range: <5.39.2
    • (no CPE)range: <5.39.2

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.