Back to search
CVE-2023-7332
Published: Dec 31, 2025
Modified: Jan 2, 2026
PUBLISHED
Description
PocketMine-MP versions prior to 4.18.1 contain an improper input validation vulnerability in inventory transaction handling. A remote attacker with a valid player session can request that the server drop more items than are available in the player's hotbar, triggering a server crash and resulting in denial of service.
| Vendor | Product | Versions |
|---|---|---|
pmmp | PocketMine-MP | affected 0 - < 4.18.1 |
Weaknesses (CWE)
References
https://github.com/pmmp/PocketMine-MP/blob/4.18.1/changelogs/4.18.md
release-notes
patch
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now