Junglewise Threat Intelligence

CVE-2022-51018: PocketMine-MP input validation bypass in book creation

CVE-2022-51018 · Severity: medium · CVSS 6.5 · Published 2026-09-07

Technologies: PocketMine-MP.

Executive brief

PocketMine-MP is a Minecraft server implementation. The server fails to validate book content limits, allowing players to create oversized books ("book bombs") that consume excessive bandwidth and crash the server by exceeding data structure limits. An attacker must first obtain a writable book in-game to exploit this vulnerability.

Technical details

The vulnerability is an input validation failure in book page handling. PocketMine-MP does not enforce limits on individual page text length, total page count, or author/title length. An authenticated player with a writable book can create oversized NBT objects that exceed protocol or storage limits: in PM3, chunks exceed the 1 MB size limit; in PM4, individual TAG_String values exceed 32 KiB. Attack requires network access and a valid game account with book access. Patches are available in versions 3.26.5 and 4.0.5.

Affected products

  • PocketMine PocketMine-MP 3.26.4 and earlier, 4.0.0–4.0.4

Timeline

  • 2022-01-04: disclosed: GitHub security advisory GHSA-p62j-hrxm-xcxf published
  • 2022: patched: Fixed in versions 3.26.5 and 4.0.5

References