Improper input validation in PocketMine-MP - #VU125417
Published: July 14, 2023 / Updated: April 8, 2026
PocketMine-MP
PMMP
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in BlockActorDataPacket handling when processing sign NBT data. A remote attacker can send a specially crafted packet with incorrect NBT tag types to cause a denial of service.
The issue was demonstrated through sign editing data, and other packet types may also be affected.