CVE-2022-51017 UNKNOWN

CVE-2022-51017

Published: 2026-09-07

Description

PocketMine-MP versions before 3.26.5 and 4.0.5 fail to validate the length of skin data fields submitted by players, allowing uncapped values to exceed the 32767 byte TAG_String limit. Attackers can submit oversized skin data fields like skinID or geometryName to trigger exceptions during NBT data serialization, causing server crashes.

AI Intelligence Brief

AI Intelligence

Analyzing vulnerability vectors…