CVE-2022-51017
PocketMine-MP versions before 3.26.5 and 4.0.5 fail to validate the length of skin data fields submitted by players, allowing uncapped values to exceed the 32767 byte TAG_String limit. Attackers can submit oversized skin data fields like skinID or geometryName to trigger exceptions during NBT data serialization, causing server crashes.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- EPSS probability
- 0.47%
- CWE
- CWE-20
- Published
- 2026-09-07
- Last modified
- 2026-09-08
Affected products
- pmmp PocketMine-MP
- pmmp PocketMine-MP
- pmmp PocketMine-MP
- pmmp PocketMine-MP
Weakness type
Related vulnerabilities
- CVE-2026-74761 — Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Spoofing of RemoveSubscription clientId
- CVE-2026-73334 — Apache Parquet Hadoop: File-controlled KMS URL is forwarded to pluggable KmsClient that skips host validation
- CVE-2025-7062 — Stored Cross-Site Scripting via file upload in H5P module (h5p-nodejs-library) of Lumi Education
- CVE-2026-12855 — H19WMIHandlerSmm: unvalidated memory boundary could result in arbitrary code execution.
- CVE-2026-87083 — tile-ai tilelang Kernel Cache kernel_cache.py KernelCache._load_kernel_from_disk deserialization
- CVE-2026-87469 — Improper input validation in Extensions in Google Chrome prior to 153.0.8010.36 allowed a remote...
- CVE-2026-87568 — Improper input validation in Chromium in Google Chrome prior to 153.0.8010.36 allowed a remote...
- CVE-2026-87510 — Improper input validation in FileAPI in Google Chrome prior to 153.0.8010.36 allowed a remote...