CVE-2023-54355
PocketMine-MP versions before 5.3.1 and 4.23.1 fail to validate that the identityPublicKey in LoginPacket uses the required secp384r1 elliptic curve. Attackers can provide LoginPackets with keys using different curves or non-EC key types to pass login verification but trigger an uncaught exception during ECDH key derivation, crashing the server.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.7
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N
- CWE
- CWE-347
- Published
- 2026-09-09
- Last modified
- 2026-09-09
Weakness type
Related vulnerabilities
- CVE-2026-79970 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-56207 — Apache Impala: SAML authentication bypass via forged bearer token
- CVE-2026-87732 — An issue was discovered in the mirage-crypto package before 2.2.0 for OCaml. The...
- CVE-2026-86080 — n8n: GitHub Trigger 422 Reuse Path Skips Webhook Secret Storage, Causing Signature Verification to Fail-Open
- CVE-2026-69646 — Skype for Business Spoofing Vulnerability
- CVE-2026-57098 — Microsoft Remote Desktop App for Windows Information Disclosure Vulnerability
- CVE-2026-14296 — nRF54H20: MCUBoot can be tricked to executing unauthenticated code
- CVE-2026-86304 — MojoX::Authentication versions before 0.006 for Perl allow SAML authentication bypass because parse_assertion builds Net::SAML2::Binding::POST without a trust anchor