CVE-2026-86204
Deferred Deferred - Pending Action

PocketMine-MP Memory Exhaustion via Malicious ModalFormResponsePacket

Vulnerability report for CVE-2026-86204, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: VulnCheck

Description

PocketMine-MP versions before 5.39.2 fail to limit JSON payload size in ModalFormResponsePacket handling, allowing authenticated players to cause denial of service. Attackers can send modal form response packets with massive JSON arrays to exhaust server memory and CPU resources, rendering the server unresponsive.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
pocketmine pocketmine-mp to 5.39.2 (exc)
pocketmine mp to 5.39.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-400 The product does not properly control the allocation and maintenance of a limited resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects PocketMine-MP server software versions before 5.39.2. It involves a flaw where the server fails to limit the size of JSON payloads in ModalFormResponsePacket handling. Authenticated players can send maliciously crafted packets with extremely large JSON arrays, causing the server to exhaust memory and CPU resources, leading to a denial of service.

Detection Guidance

Monitor server resource usage for sudden spikes in memory or CPU consumption, particularly when players interact with forms. Check server logs for unusually large ModalFormResponsePacket payloads or form responses exceeding 10 KB. Use network monitoring tools to detect large JSON arrays being sent to the server.

Impact Analysis

If you run a PocketMine-MP server using a vulnerable version, an attacker with a player account could disrupt your server by sending oversized JSON payloads. This would make the server unresponsive, affecting all players and potentially causing downtime.

Compliance Impact

This vulnerability primarily causes server unavailability by exhausting memory and CPU resources, which could lead to disruptions in data processing or service delivery. For GDPR, this may impact availability of personal data processing systems. For HIPAA, it could disrupt healthcare services relying on the server. However, the vulnerability itself does not directly expose or leak data, so compliance impact is indirect through service disruption rather than data breaches.

Mitigation Strategies

Upgrade PocketMine-MP to version 5.39.2 or later to apply the official patch. If upgrading is not immediately possible, implement network-level restrictions to block oversized packets or limit form response sizes. Temporarily disable non-essential forms to reduce attack surface until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86204. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart