CVE-2022-51017

PocketMine-MP versions before 3.26.5 and 4.0.5 fail to validate the length of skin data fields submitted by players, allowing uncapped values to exceed the 32767 byte TAG_String limit. Attackers can submit oversized skin data fields like skinID or geometryName to trigger exceptions during NBT data serialization, causing server crashes.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-07 13:17

Updated : 2026-09-08 19:59


NVD link : CVE-2022-51017

Mitre link : CVE-2022-51017

CVE.ORG link : CVE-2022-51017


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation