PocketMine-MP versions before 5.39.2 contain a network amplification vulnerability in ActorEventPacket handling that allows clients to trigger consuming animations for all visible players. Attackers can send crafted ActorEventPacket messages to spam animation events to other clients and waste server CPU and memory resources.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Wed, 09 Sep 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PocketMine-MP versions before 5.39.2 contain a network amplification vulnerability in ActorEventPacket handling that allows clients to trigger consuming animations for all visible players. Attackers can send crafted ActorEventPacket messages to spam animation events to other clients and waste server CPU and memory resources. | |
| Title | PocketMine-MP before 5.39.2 Network Amplification via ActorEventPacket | |
| Weaknesses | CWE-406 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-09T14:45:30.860Z
Reserved: 2026-09-05T11:52:36.821Z
Link: CVE-2026-86202
No data.
Status : Received
Published: 2026-09-09T14:17:21.400
Modified: 2026-09-09T14:17:21.400
Link: CVE-2026-86202
No data.
OpenCVE Enrichment
No data.
Weaknesses