CVE-2020-37277CWE-400denial-of-service

CVE-2020-37277

Medium · published September 6, 2026

CVSS v3.1
6.5
EPSS
In the wild
Unconfirmed
What it is

PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send specially crafted InventoryTransactionPackets with multiple conflicting pathways to cause exponential processing complexity, freezing the server.

The record
Technical detail
CVSS v3.1
6.5 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
7.1 · CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS
Not scored
Weakness
CWE-400 · Uncontrolled Resource Consumption
Published
2026-09-06T16:17Z
References (3)
Timeline
  • 06 SEP 12:00Z
    PocketMine-MP before 3.15.4 Denial of Service via InventoryTransaction
    cvelistv5