CVE-2023-54396

PocketMine-MP versions before 4.8.1 fail to validate dye color IDs in banner NBT data during deserialization. Attackers can provide invalid color values in inventory transactions or via commands to trigger undefined offset errors and crash the server.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-09 14:17

Updated : 2026-09-09 20:20


NVD link : CVE-2023-54396

Mitre link : CVE-2023-54396

CVE.ORG link : CVE-2023-54396


JSON object : View

Products Affected

No product.

CWE
CWE-129

Improper Validation of Array Index