CVE-2026-86201
Deferred Deferred - Pending Action

Denial of Service in PocketMine-MP via Malicious LoginPacket

Vulnerability report for CVE-2026-86201, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: VulnCheck

Description

PocketMine-MP before 5.41.1 contains a denial of service vulnerability in LoginPacket processing where large or complex structures in unknown clientData JWT properties cause excessive logging without sanitization. Attackers can send crafted LoginPackets with deeply nested or massive object structures to trigger out-of-memory conditions and crash the server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-29
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
pocketmine pocketmine-mp to 5.41.1 (exc)
pocketmine mp to 5.41.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-86201 is a denial of service vulnerability in PocketMine-MP versions before 5.41.1. It involves attackers sending crafted LoginPackets with large or complex structures in unknown clientData JWT properties. This causes excessive logging without sanitization, leading to out-of-memory conditions and server crashes.

Detection Guidance

Monitor server logs for unusually long or frequent log entries during client login attempts. Check for excessive CPU usage or memory consumption spikes when clients connect. Use network traffic analysis tools to inspect LoginPacket structures for deeply nested or large object properties in clientData JWTs.

Impact Analysis

This vulnerability allows remote attackers to crash PocketMine-MP servers by sending specially crafted packets. It requires no privileges or user interaction, making it easy to exploit. Servers may experience downtime, performance degradation, or complete crashes due to out-of-memory errors.

Compliance Impact

This vulnerability primarily causes denial of service by crashing servers through excessive logging and memory exhaustion. It does not directly impact data confidentiality or integrity, which are key concerns for GDPR and HIPAA. However, prolonged downtime could affect service availability, potentially violating availability requirements in these regulations.

Mitigation Strategies

Upgrade PocketMine-MP to version 5.41.1 or later. If upgrading is not immediately possible, enable the bExceptionOnUndefinedProperty flag in JsonMapper settings to reject unexpected properties, though this may cause login failures for some clients.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86201. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart