PocketMine-MP before 5.11.1 contains a denial of service vulnerability in LoginPacket JSON processing that allows remote attackers to crash the server by sending malformed JSON data. Attackers can exploit improper object initialization from scalar JSON types to trigger unset required properties, causing the application to crash.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-09 14:17
Updated : 2026-09-14 14:17
NVD link : CVE-2024-58381
Mitre link : CVE-2024-58381
CVE.ORG link : CVE-2024-58381
JSON object : View
Products Affected
No product.
CWE
CWE-502
Deserialization of Untrusted Data
