PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket position and rotation fields. Malicious clients can send crafted movement packets with invalid floating-point values to crash servers through unhandled mathematical operations or prevent clients from rendering other players.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Sun, 06 Sep 2026 12:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket position and rotation fields. Malicious clients can send crafted movement packets with invalid floating-point values to crash servers through unhandled mathematical operations or prevent clients from rendering other players. | |
| Title | PocketMine-MP before 3.18.1 Denial of Service via MovePlayerPacket | |
| Weaknesses | CWE-20 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-06T12:50:16.713Z
Reserved: 2026-09-05T21:04:52.479Z
Link: CVE-2021-48007
No data.
Status : Received
Published: 2026-09-06T12:17:14.783
Modified: 2026-09-06T13:17:10.077
Link: CVE-2021-48007
No data.
OpenCVE Enrichment
Updated: 2026-09-06T13:30:07Z
Weaknesses