Junglewise Threat Intelligence

CVE-2023-54394: PocketMine-MP missing rate-limit for mismatch inventory transactions

CVE-2023-54394 · Severity: medium · CVSS 4.3 · Published 2026-09-09

Technologies: pocketmine/pocketmine-mp (Packagist), PocketMine-MP. Vendors: Packagist.

Executive brief

PocketMine-MP is a Minecraft server implementation that manages player inventories and item synchronization. An attacker can send mismatch inventory transaction requests without rate-limiting, forcing the server to send large amounts of serialized inventory data repeatedly, consuming significant bandwidth and potentially degrading server performance for legitimate players.

Technical details

PocketMine-MP fails to rate-limit "mismatch" type InventoryTransactionPacket requests, which are used by clients to request a resync of all open inventories. An attacker with network access and low privileges (ability to connect as a player) can send numerous mismatch transactions per tick, causing the server to synchronize and transmit large amounts of serialized inventory data repeatedly. Since network-serialized inventory items can be very large (especially with NBT data), this acts as a bandwidth amplification attack. The vulnerability was patched in version 4.18.0-ALPHA2 by deferring inventory synchronization until the end of the tick and implementing the ItemStackRequest system.

Affected products

  • PocketMine PocketMine-MP before 4.18.0-ALPHA2

Timeline

  • 2023-05-30: disclosed
  • 2023-03-20: patched: Fix commit ca6d514 merged; patch released in version 4.18.0-ALPHA2
  • 2023-05-30: advisory: GHSA-42qm-8v8m-m78c published

References

Related threats