CVE-2023-54393
Deferred Deferred - Pending Action

Denial of Service in PocketMine-MP via LoginPacket JSON Parsing

Vulnerability report for CVE-2023-54393, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: VulnCheck

Description

PocketMine-MP versions before 4.20.5 contain a denial of service vulnerability in LoginPacket JSON parsing due to improper validation in the JsonMapper dependency. Attackers can send malformed JSON structures in LoginPacket to crash the server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-28
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pocketmine mp to 4.20.5 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a denial of service (DoS) flaw in PocketMine-MP versions before 4.20.5. It occurs due to improper validation in the JsonMapper dependency during LoginPacket JSON parsing. Attackers can send malformed JSON structures in LoginPacket to crash the server.

Detection Guidance

Monitor server logs for crashes during LoginPacket processing. Use plugins to catch DataPacketReceiveEvent exceptions or detect malformed JSON payloads. Check PocketMine-MP version; if below 4.20.5, the system is vulnerable.

Impact Analysis

This vulnerability can allow attackers to crash PocketMine-MP servers by sending specially crafted malformed JSON in LoginPacket. This results in denial of service, making the server unavailable until restarted. Servers using vulnerable versions are at risk of unexpected downtime.

Compliance Impact

This vulnerability primarily impacts availability by allowing denial of service attacks through server crashes. While it does not directly expose or leak data, prolonged downtime could lead to violations of service availability requirements in GDPR, HIPAA, or other regulations that mandate timely access to systems or data. The severity depends on the system's role and the duration of disruption.

Mitigation Strategies

Upgrade PocketMine-MP to version 4.20.5 or later. If using source installations, manually apply the JsonMapper fork patch or use a plugin to block suspicious LoginPacket payloads.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2023-54393. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart