Logging of Excessive Data in PocketMine-MP - #VU132306
Published: May 26, 2026
PocketMine-MP
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to logging of excessive data in the LoginPacket handler when processing the clientData JWT body. A remote attacker can send a crafted LoginPacket containing many junk properties to cause a denial of service.
The issue can flood warning logs and waste CPU time.