CVE-2022-51012
Received Received - Intake

Denial of Service in PocketMine-MP via Malformed NBT Tags

Vulnerability report for CVE-2022-51012, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-07

Last updated on: 2026-09-07

Assigner: VulnCheck

Description

PocketMine-MP versions before 4.2.9 fail to properly validate NBT data types during deserialization of inventory transaction packets from clients. Attackers can send crafted inventory transactions with malformed NBT tags to trigger server crashes and cause denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-07
Last Modified
2026-09-07
Generated
2026-09-07
AI Q&A
2026-09-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
pocketmine mp to 4.2.9 (exc)
pocketmine pocketmine-mp to 4.2.9 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

PocketMine-MP versions before 4.2.9 fail to properly validate NBT data types during deserialization of inventory transaction packets from clients. Attackers can send crafted inventory transactions with malformed NBT tags to trigger server crashes and cause denial of service.

Detection Guidance

Monitor PocketMine-MP server logs for crashes or errors related to NBT deserialization during inventory transactions. Check for malformed NBT tags in client-sent packets. Use network monitoring tools to inspect traffic for unusual inventory transaction patterns targeting the server.

Impact Analysis

This vulnerability allows attackers to crash PocketMine-MP servers by sending malformed NBT data in inventory transactions. This results in denial of service, making the server unavailable for legitimate users.

Compliance Impact

This vulnerability primarily causes server crashes due to improper input validation, leading to denial of service. It does not directly affect compliance with standards like GDPR or HIPAA as it does not involve data breaches or unauthorized access. However, prolonged downtime could impact service availability, which may indirectly affect compliance with availability requirements in regulations.

Mitigation Strategies

Upgrade PocketMine-MP to version 4.2.9 or later to apply the patch that fixes NBT type validation issues. If upgrading is not immediately possible, restrict network access to the server or disable inventory transaction processing until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2022-51012. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart