Improper input validation in PocketMine-MP - CVE-2023-7332
Published: May 30, 2023 / Updated: April 8, 2026
PocketMine-MP
PMMP
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in inventory network handling when processing dropped item count requests. A remote attacker can request that the server drop more of an item than is available in the hotbar to cause a denial of service.
The issue does not result in item duplication.