CVE-2023-54392: Pmmp Pocketmine-Mp
Medium severity, CVSS 6.5. EPSS: 0.4% chance of exploitation in the next 30 days.
PocketMine-MP versions >= 4.20.0 before 4.22.3 (and before 5.2.1 in the 5.x branch) fail to validate NBT tag types in BlockActorDataPacket. A player can crash the server by sending a packet containing sign NBT data with an incorrect tag type, triggering an unhandled UnexpectedTagTypeException that terminates the server process.
Affected products
- Pmmp Pocketmine-Mp: from 4.20.0, before 4.22.3 (fixed in 4.22.3); from 5.0.0, before 5.2.1 (fixed in 5.2.1)
Published 2026-09-09. Last modified 2026-10-08.