Get real-time updates on Telegram
CVE-2023-54394: PocketMine-MP 0 to before 4.18.0-ALPHA2
CVE-2023-54394. CVSS 3.1 base score 4.3 (MEDIUM, Vendor/CNA). EPSS 0.00379 (percentile 0.29613), scored 2026-10-06.
Affected technology
PocketMine-MP · 0 to before 4.18.0-ALPHA2
pmmp
Description’s affected range: before 4.18.0-ALPHA2 fails to rate-limit mismatch type InventoryTransactionPacket requests
Component: Not specified by the source
Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · Low privileges required · No user interaction required
What an attacker can do
Attackers can send numerous mismatch transactions to force the server to transmit large amounts of serialized inventory data, consuming significant bandwidth without authentication. Vendor/CNA’s CVSS 4.0 assessment (base score 5.3/10) rates confidentiality and integrity impact as none; availability impact as low.
- CWE
- CWE-770
- CCR priority
- 17.3 /100 (P5)
- CVSS 3.1
- 4.3 /10 · CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L · Vendor/CNA
- EPSS
- 0.00379 · percentile 0.29726 · 2026-10-08
- KEV
- no
Provenance
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-08 17:36:22.845483+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-08 17:32:11.049884+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2023-54394.html