Improper input validation in PocketMine-MP - #VU125423
Published: September 13, 2023 / Updated: April 8, 2026
PocketMine-MP
PMMP
Description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper input validation in LoginPacket identityPublicKey handling when processing login packets containing a public key on an incorrect elliptic curve or a non-EC key. A remote attacker can send a specially crafted login packet to cause a denial of service.
The issue is triggered after the login chain is successfully verified, when ECDH key derivation encounters a client-provided key that does not belong to the server's curve.