CVE-2022-51009: Pmmp Pocketmine-Mp
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin packets with invalid geometry JSON to trigger an unhandled RuntimeException, causing server crash.
Affected products
- Pmmp Pocketmine-Mp: before 4.7.2 (fixed in 4.7.2)
Published 2026-09-06. Last modified 2026-10-08.