Executive brief
PocketMine-MP is a popular Minecraft server software used to host multiplayer game servers. An attacker connected to a server can send specially crafted network packets to force other players' clients to repeatedly perform animations (such as eating or drinking), consuming their bandwidth, CPU, and memory. By amplifying a small number of malicious packets into many animation events sent to all visible players, this can disrupt server performance and degrade the experience for legitimate players.
Technical details
The vulnerability is a network amplification flaw (CWE-406) in how PocketMine-MP handles ActorEventPacket messages received from clients. The server processes these packets without sufficient validation and broadcasts animation events to all nearby players, allowing an authenticated client to send a single malicious packet that triggers multiple outbound animation packets to other clients. Attack requires network access to a PocketMine-MP server and low-privilege player authentication; no user interaction is needed. An attacker can waste server resources (CPU, memory, bandwidth) and potentially disrupt game experience. The vulnerability was patched in version 5.39.2 by changing animation handling to be fully server-controlled and discarding client-originated ActorEventPacket messages.
Affected products
- PocketMine PocketMine-MP before 5.39.2
Timeline
- 2026-04-04: disclosed: GHSA-7hmv-4j2j-pp6f published
- 2026-05-09: patched: Version 5.39.2 released with fix
- 2026-09-09: other: CVE-2026-86202 assigned