CVE-2020-37277

PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send specially crafted InventoryTransactionPackets with multiple conflicting pathways to cause exponential processing complexity, freezing the server.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-06 12:17

Updated : 2026-09-08 20:05


NVD link : CVE-2020-37277

Mitre link : CVE-2020-37277

CVE.ORG link : CVE-2020-37277


JSON object : View

Products Affected

No product.

CWE
CWE-400

Uncontrolled Resource Consumption