PocketMine-MP versions before 5.39.2 fail to limit JSON payload size in ModalFormResponsePacket handling, allowing authenticated players to cause denial of service. Attackers can send modal form response packets with massive JSON arrays to exhaust server memory and CPU resources, rendering the server unresponsive.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-09 14:17
Updated : 2026-09-09 20:20
NVD link : CVE-2026-86204
Mitre link : CVE-2026-86204
CVE.ORG link : CVE-2026-86204
JSON object : View
Products Affected
No product.
CWE
CWE-400
Uncontrolled Resource Consumption
