CVE-2022-51009CWE-248

PocketMine-MP before 4.7.2 Denial of Service via Skin Geometry

High · published September 6, 2026

CVSS v3.1
7.5
EPSS
In the wild
Unconfirmed
What it is

PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin packets with invalid geometry JSON to trigger an unhandled RuntimeException, causing server crash.

The record
Technical detail
CVSS v3.1
7.5 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS v4.0
8.7 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
EPSS
Not scored
Weakness
CWE-248 · Uncaught Exception
Published
2026-09-06T12:00Z
Timeline
  • 06 SEP 12:00Z
    PocketMine-MP before 4.7.2 Denial of Service via Skin Geometry
    cvelistv5