Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 07 Sep 2026 13:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PocketMine-MP versions before 3.26.5 and 4.0.5 fail to validate the length of skin data fields submitted by players, allowing uncapped values to exceed the 32767 byte TAG_String limit. Attackers can submit oversized skin data fields like skinID or geometryName to trigger exceptions during NBT data serialization, causing server crashes. | |
| Title | PocketMine-MP before 3.26.5 and 4.0.5 Denial of Service via Skin Data | |
| Weaknesses | CWE-20 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-07T12:55:09.862Z
Reserved: 2026-09-05T21:03:47.627Z
Link: CVE-2022-51017
No data.
Status : Received
Published: 2026-09-07T13:17:23.747
Modified: 2026-09-07T13:17:23.747
Link: CVE-2022-51017
No data.
OpenCVE Enrichment
No data.