CVE-2023-54392
Deferred Deferred - Pending Action

PocketMine-MP Server Crash via Invalid NBT Tag Type

Vulnerability report for CVE-2023-54392, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-18

Assigner: VulnCheck

Description

PocketMine-MP versions >= 4.20.0 before 4.22.3 (and before 5.2.1 in the 5.x branch) fail to validate NBT tag types in BlockActorDataPacket. A player can crash the server by sending a packet containing sign NBT data with an incorrect tag type, triggering an unhandled UnexpectedTagTypeException that terminates the server process.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-18
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-28
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
pocketmine pocketmine-mp From 4.20.0 (inc) to 4.22.3 (exc)
pocketmine pocketmine-mp to 5.2.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects PocketMine-MP server software versions 4.20.0 and above (before 4.22.3) and 5.x branch before 5.2.1. It involves improper validation of NBT tag types in the BlockActorDataPacket. Attackers can crash the server by sending a maliciously crafted packet with incorrect sign NBT data, specifically using a ByteTag instead of the expected CompoundTag for the FrontText field. This triggers an unhandled exception, causing the server to terminate and resulting in a denial of service.

Detection Guidance

Monitor PocketMine-MP server logs for UnexpectedTagTypeException errors during sign editing. Check for server crashes when players interact with signs. Use network traffic analysis tools to inspect BlockActorDataPacket contents for malformed NBT data with incorrect tag types.

Impact Analysis

The primary impact is server downtime due to crashes. Since the vulnerability requires minimal privileges and no user interaction, any player can exploit it by editing a sign with improperly formatted NBT data. This leads to a denial of service, making the server unavailable for all users until it is restarted. The attack does not compromise data integrity or confidentiality but disrupts normal server operations.

Compliance Impact

This vulnerability primarily impacts availability, which is a key aspect of compliance for standards like GDPR and HIPAA. A denial of service could lead to prolonged downtime, potentially violating service level agreements or regulatory requirements for data accessibility. However, there is no evidence of data exposure or modification, so confidentiality and integrity aspects are not directly affected.

Mitigation Strategies

Upgrade PocketMine-MP to version 4.22.3 or later (or 5.2.1 for 5.x branch). If immediate upgrade is not possible, implement a plugin to intercept BlockActorDataPacket via DataPacketReceiveEvent and validate FrontText tag types before processing.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2023-54392. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart