CVE-2026-86202
PocketMine-MP versions before 5.39.2 contain a network amplification vulnerability in ActorEventPacket handling that allows clients to trigger consuming animations for all visible players. Attackers can send crafted ActorEventPacket messages to spam animation events to other clients and waste server CPU and memory resources.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
- CWE
- CWE-406
- Published
- 2026-09-09
- Last modified
- 2026-09-09
Affected products
- pmmp PocketMine-MP
- pmmp PocketMine-MP
Weakness type
Related vulnerabilities
- CVE-2026-68080 — Apache Qpid Broker-J: Unbounded echo flow responses can lead to denial of service
- CVE-2026-54609 — QTINeon has unauthenticated relay-to-host amplification via unbounded RECONNECT_REQUEST forwarding
- CVE-2026-50045 — 'max-global-quota' reset by DNSSEC validation restarts
- CVE-2026-45557 — Technitium DNS Server excessive DNSSEC requests
- CVE-2025-58066 — DoS Vulnerability in ntpd-rs
- CVE-2021-38135 — Possible External service interaction Vulnerability in OpenText iManager
- CVE-2024-25015 — IBM MQ denial of service
- CVE-2014-125036 — drybjed ansible-ntp main.yml amplification