CVE-2026-86203
PocketMine-MP versions before 5.39.2 fail to validate entity despawn state when processing attack packets from clients. Attackers can exploit a race condition by attacking a disconnecting player to trigger multiple death handlers, causing inventory items and experience to drop multiple times for duplication.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.3
- CVSS vector
- CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.27%
- CWE
- CWE-664
- Published
- 2026-09-09
- Last modified
- 2026-09-10
Affected products
- pmmp PocketMine-MP
- pmmp PocketMine-MP
Weakness type
Related vulnerabilities
- CVE-2026-20274 — Cisco IOS XR Software Security Hardening Release: September 2026
- CVE-2026-79289 — Improper control of a resource through its lifetime in Workers in Google Chrome prior to...
- CVE-2026-18549 — @fastify/multipart vulnerable to Denial of Service via aborted upload after fileSize limit
- CVE-2026-19380 — Mullvad wireguard.sys IOCTL AdapterState reference count
- CVE-2026-20269 — Cisco IOS XE Software Security Hardening Release
- CVE-2026-20158 — Cisco RoomOS Security Hardening Release - Resource Lifetime Management Vulnerabilities
- CVE-2025-34226 — OpenPLC Runtime v3 Persistent DoS
- CVE-2025-54621 — Iterator failure issue in the WantAgent module....