PocketMine-MP before 4.12.3 fails to limit unauthenticated sessions, allowing attackers to exhaust player slots by creating sessions without sending LoginPacket. Attackers can flood the server with unauthenticated connections that occupy max-player slots, preventing legitimate players from joining.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 06 Sep 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PocketMine-MP before 4.12.3 fails to limit unauthenticated sessions, allowing attackers to exhaust player slots by creating sessions without sending LoginPacket. Attackers can flood the server with unauthenticated connections that occupy max-player slots, preventing legitimate players from joining. | |
| Title | PocketMine-MP before 4.12.3 Denial of Service via Unauthenticated Sessions | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-06T12:50:17.386Z
Reserved: 2026-09-05T21:00:28.837Z
Link: CVE-2022-51008
No data.
Status : Received
Published: 2026-09-06T12:17:14.930
Modified: 2026-09-06T13:17:10.203
Link: CVE-2022-51008
No data.
OpenCVE Enrichment
Updated: 2026-09-06T13:30:07Z
Weaknesses