PocketMine-MP versions before 4.12.5 contain a denial-of...
Moderate severity
Unreviewed
Published
Sep 9, 2026
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Sep 9, 2026
Published to the GitHub Advisory Database
Sep 9, 2026
PocketMine-MP versions before 4.12.5 contain a denial-of-service vulnerability in ModalFormResponsePacket processing that allows attackers to cause server resource exhaustion by sending large JSON payloads. Attackers can send numerous oversized modal form response packets to consume CPU time and prevent the server from processing legitimate connections.
References