CVE-2026-86200

PocketMine-MP versions before 5.42.1 contain a denial of service vulnerability in the LoginPacket handler that allows remote attackers to flood warning messages by injecting numerous junk properties into the clientData JWT. Attackers can craft malicious login packets with excessive unknown properties to waste server CPU time and degrade performance.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-09 14:17

Updated : 2026-09-09 20:20


NVD link : CVE-2026-86200

Mitre link : CVE-2026-86200

CVE.ORG link : CVE-2026-86200


JSON object : View

Products Affected

No product.

CWE
CWE-779

Logging of Excessive Data