PocketMine-MP versions before 5.3.1 and 4.23.1 fail to validate that the identityPublicKey in LoginPacket uses the required secp384r1 elliptic curve. Attackers can provide LoginPackets with keys using different curves or non-EC key types to pass login verification but trigger an uncaught exception during ECDH key derivation, crashing the server.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-09 14:17
Updated : 2026-09-10 15:17
NVD link : CVE-2023-54355
Mitre link : CVE-2023-54355
CVE.ORG link : CVE-2023-54355
JSON object : View
Products Affected
No product.
CWE
CWE-347
Improper Verification of Cryptographic Signature
