Incomplete List of Disallowed Inputs in PocketMine-MP - #VU132307
Published: May 26, 2026
PocketMine-MP
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to incomplete list of disallowed inputs in the offline login flow when handling login requests from players without Xbox authentication. A remote attacker can send a login request without Xbox authentication to cause a denial of service.
The issue occurs before the player is fully rejected.