Medium severity6.5NVD Advisory· Published Sep 9, 2026· Updated Sep 9, 2026
CVE-2026-86204
CVE-2026-86204
Description
PocketMine-MP versions before 5.39.2 fail to limit JSON payload size in ModalFormResponsePacket handling, allowing authenticated players to cause denial of service. Attackers can send modal form response packets with massive JSON arrays to exhaust server memory and CPU resources, rendering the server unresponsive.
Affected products
2<5.39.2+ 1 more
- (no CPE)range: <5.39.2
- (no CPE)range: <5.39.2
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.