CVE-2024-58381
Deferred Deferred - Pending Action

Denial of Service in PocketMine-MP via Malformed LoginPacket JSON

Vulnerability report for CVE-2024-58381, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: VulnCheck

Description

PocketMine-MP before 5.11.1 contains a denial of service vulnerability in LoginPacket JSON processing that allows remote attackers to crash the server by sending malformed JSON data. Attackers can exploit improper object initialization from scalar JSON types to trigger unset required properties, causing the application to crash.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
pocketmine mp to 5.11.1 (exc)
pocketmine pocketmine-mp to 5.11.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-502 The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2024-58381 is a denial of service vulnerability in PocketMine-MP versions before 5.11.1. It involves improper handling of malformed JSON data during login packet processing. Attackers can send specially crafted JSON to crash the server by causing unset required properties in objects due to improper object initialization from scalar JSON types.

Detection Guidance

Monitor PocketMine-MP server logs for crashes during login attempts. Check for malformed JSON errors in logs. Use network traffic analysis tools like Wireshark to inspect LoginPacket data for unusual JSON structures. Ensure your server runs version 5.11.1 or later to confirm patch application.

Impact Analysis

This vulnerability allows remote attackers to disrupt server availability by crashing the PocketMine-MP server. It requires no privileges or user interaction and can be exploited over the network with low complexity. Servers running vulnerable versions may become unresponsive or crash when processing login requests with malformed JSON.

Compliance Impact

This vulnerability primarily impacts availability by causing server crashes through malformed JSON data. While it does not directly expose or leak data, prolonged downtime could violate compliance requirements for availability in standards like GDPR (Article 32) or HIPAA (Security Rule). However, the vulnerability does not directly affect confidentiality or integrity of data.

Mitigation Strategies

Upgrade PocketMine-MP to version 5.11.1 or later immediately. If upgrading is not possible, restrict network access to the server or disable login functionality temporarily. Monitor for unusual traffic patterns targeting the login endpoint.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2024-58381. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart