PocketMine-MP versions before 3.26.5 and 4.0.5 fail to validate the length of skin data fields submitted by players, allowing uncapped values to exceed the 32767 byte TAG_String limit. Attackers can submit oversized skin data fields like skinID or geometryName to trigger exceptions during NBT data serialization, causing server crashes.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-07 13:17
Updated : 2026-09-08 19:59
NVD link : CVE-2022-51017
Mitre link : CVE-2022-51017
CVE.ORG link : CVE-2022-51017
JSON object : View
Products Affected
No product.
CWE
CWE-20
Improper Input Validation
