PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send specially crafted InventoryTransactionPackets with multiple conflicting pathways to cause exponential processing complexity, freezing the server.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-06 12:17
Updated : 2026-09-08 20:05
NVD link : CVE-2020-37277
Mitre link : CVE-2020-37277
CVE.ORG link : CVE-2020-37277
JSON object : View
Products Affected
No product.
CWE
CWE-400
Uncontrolled Resource Consumption
