PocketMine-MP before 4.2.10 fails to validate the total length of incoming chat message blobs before splitting them by newline characters, allowing attackers to send large messages containing many newlines. Malicious clients can send megabyte-sized chat packets and bombard the server with thousands of such messages, causing server lockups lasting seconds or minutes.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-07 13:17
Updated : 2026-09-10 16:17
NVD link : CVE-2022-51011
Mitre link : CVE-2022-51011
CVE.ORG link : CVE-2022-51011
JSON object : View
Products Affected
No product.
CWE
CWE-20
Improper Input Validation
