Junglewise Threat Intelligence

CVE-2023-54355: PocketMine-MP EC key validation bypass in LoginPacket

CVE-2023-54355 · Severity: high · CVSS 7.5 · Published 2026-09-09

Technologies: pocketmine/pocketmine-mp (Packagist), PocketMine-MP. Vendors: Packagist.

Executive brief

PocketMine-MP is a Minecraft server implementation used to host multiplayer game sessions. Versions before 5.3.1 and 4.23.1 fail to properly validate cryptographic keys during player login, allowing attackers to crash servers with specially crafted login packets. This denial-of-service attack requires no authentication and can be exploited by remote unauthenticated users.

Technical details

The vulnerability is an input validation flaw in the LoginPacket handler. PocketMine-MP uses ECDH (Elliptic Curve Diffie-Hellman) with the secp384r1 curve for deriving symmetric encryption keys after login; however, the server failed to validate that client-supplied identityPublicKey values actually use this curve. An attacker can provide LoginPackets with keys using different curves (e.g. secp256r1) or non-EC key types (e.g. RSA, DH) that still pass JWT signature verification but trigger an uncaught exception during ECDH key derivation. The attack is network-accessible, requires no authentication or user interaction, and crashes the server (denial of service). Patches were released in versions 4.23.1 and 5.3.1.

Affected products

  • PocketMine PocketMine-MP before 4.23.1 and 5.3.1

Timeline

  • 2023-09-13: disclosed
  • 2023-09-13: patched: versions 4.23.1 and 5.3.1 released

References

Related threats