# CVE-2023-54396

## Summary

- **CVE ID:** CVE-2023-54396
- **Severity:** HIGH
- **CVSS Score:** 7.1 (CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-129
- **Published:** Sep 9, 2026
- **Last Modified:** Sep 9, 2026

## Description

PocketMine-MP versions before 4.8.1 fail to validate dye color IDs in banner NBT data during deserialization. Attackers can provide invalid color values in inventory transactions or via commands to trigger undefined offset errors and crash the server.

## Affected Products

- pmmp — PocketMine-MP (0)
- pmmp — PocketMine-MP (4.8.1)

## References

- [CNA](https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-wqqv-jcfr-9f5g)
- [CNA](https://github.com/pmmp/PocketMine-MP/commit/08b9495bce2d65a6d1d3eeb76e484499a00765eb)
- [CNA](https://www.vulncheck.com/advisories/pocketmine-mp-before-4.8.1-server-crash-via-banner-nbt)

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-10._