CVE-2024-58380
Deferred Deferred - Pending Action

BookEditPacket Denial of Service in PocketMine-MP

Vulnerability report for CVE-2024-58380, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-18

Assigner: VulnCheck

Description

PocketMine-MP versions before 5.11.2 contain a denial of service vulnerability in BookEditPacket handling that crashes the server when an invalid inventory slot value is provided. Attackers can send a crafted BookEditPacket with an inventory slot greater than 35 to trigger an unhandled exception and crash the server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-18
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
pocketmine mp to 5.11.2 (exc)
pocketmine pocketmine-mp to 5.11.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a denial of service vulnerability in PocketMine-MP versions before 5.11.2. It involves sending a crafted BookEditPacket with an inventory slot value greater than 35, which causes an unhandled exception and crashes the server due to improper input validation.

Detection Guidance

Monitor PocketMine-MP server logs for crashes or unhandled exceptions related to BookEditPacket handling. Check for packets with inventory slot values greater than 35. Use network monitoring tools to inspect incoming packets for malformed BookEditPacket structures.

Impact Analysis

This vulnerability allows attackers to remotely crash PocketMine-MP servers by sending a specially crafted packet. This results in server downtime and disrupts service for all users connected to the server.

Compliance Impact

This vulnerability primarily impacts server availability by causing crashes, which could disrupt services handling sensitive data. For GDPR, repeated crashes may affect data processing operations requiring high availability. For HIPAA, server downtime could interrupt access to protected health information, potentially violating access controls or audit requirements.

Mitigation Strategies

Update PocketMine-MP to version 5.11.2 or later to apply the security patch. If immediate update is not possible, restrict network access to the server or implement packet filtering to block BookEditPackets with inventory slot values exceeding 35.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2024-58380. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart