CVE-2023-54394
Deferred Deferred - Pending Action

PocketMine-MP InventoryTransactionPacket Type Mismatch Rate-Limit Bypass

Vulnerability report for CVE-2023-54394, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: VulnCheck

Description

PocketMine-MP before 4.18.0-ALPHA2 fails to rate-limit mismatch type InventoryTransactionPacket requests, allowing attackers to trigger excessive inventory synchronization. Attackers can send numerous mismatch transactions to force the server to transmit large amounts of serialized inventory data, consuming significant bandwidth without authentication.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pocketmine pocketmine-mp to 4.18.0-ALPHA2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects PocketMine-MP versions before 4.18.0-ALPHA2. It allows attackers to send numerous InventoryTransactionPacket requests with mismatched types without rate-limiting. This forces the server to repeatedly synchronize and transmit large amounts of serialized inventory data, consuming significant bandwidth without authentication.

Detection Guidance

Monitor network traffic for unusually high bandwidth usage from PocketMine-MP servers, particularly involving InventoryTransactionPacket requests with mismatch types. Check server logs for repeated inventory synchronization events or large serialized data transmissions.

Impact Analysis

The vulnerability can lead to excessive bandwidth usage on the server, potentially causing network congestion or service disruption. Servers hosting large inventories with complex NBT data are most affected. Attackers do not need authentication but require some privileges to exploit this issue.

Compliance Impact

This vulnerability primarily causes excessive bandwidth consumption due to uncontrolled inventory synchronization, which could lead to service disruptions or degraded performance. While it does not directly expose or leak sensitive data, the resulting resource exhaustion may impact availability, a key aspect of compliance for standards like GDPR (data availability) and HIPAA (system integrity). However, there is no evidence this vulnerability results in unauthorized data access or disclosure.

Mitigation Strategies
  • Upgrade PocketMine-MP to version 4.18.0-ALPHA2 or later to apply the official patch.
  • Implement rate-limiting plugins to restrict mismatch transaction packets to one per tick.
  • Monitor server bandwidth usage and block suspicious traffic patterns.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2023-54394. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart