PocketMine-MP versions before 5.39.2 contain a network amplification vulnerability in ActorEventPacket handling that allows clients to trigger consuming animations for all visible players. Attackers can send crafted ActorEventPacket messages to spam animation events to other clients and waste server CPU and memory resources.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-09 14:17
Updated : 2026-09-09 20:20
NVD link : CVE-2026-86202
Mitre link : CVE-2026-86202
CVE.ORG link : CVE-2026-86202
JSON object : View
Products Affected
No product.
CWE
CWE-406
Insufficient Control of Network Message Volume (Network Amplification)
