Junglewise Threat Intelligence

CVE-2022-51013: PocketMine-MP input validation bypass in item damage metadata

CVE-2022-51013 · Severity: medium · CVSS 6.5 · Published 2026-09-07

Technologies: pocketmine/pocketmine-mp (Packagist), PocketMine-MP. Vendors: Packagist.

Executive brief

PocketMine-MP is a popular Minecraft Bedrock Edition server software. A validation flaw allows attackers to send malformed tool and armor item data with negative or out-of-range damage values, causing the server to crash. This availability impact affects game operations and player experience.

Technical details

PocketMine-MP versions before 4.2.3 fail to validate damage metadata values in tool and armor item NBT data received from clients. The vulnerability exists in the TypeConverter class, which blindly uses metadata values from client-sent itemstack NBT without range checking. When an attacker sends negative or out-of-range damage values (outside 0-0x7fff), the Durable class throws an unhandled exception, crashing the server. The attack requires network access and low privileges (ability to send game packets), with no user interaction needed. Patch version 4.2.4 adds explicit range validation in TypeConverter before processing the metadata.

Affected products

  • PocketMine PocketMine-MP before 4.2.3

Timeline

  • 2022-03-18: disclosed
  • 2022: patched: patch version 4.2.4 released

References

Related threats