CVE-2023-7332

Pocketmine-mp < 4.18.1 - Denial of Service

Title source: rule

Description

PocketMine-MP versions prior to 4.18.1 contain an improper input validation vulnerability in inventory transaction handling. A remote attacker with a valid player session can request that the server drop more items than are available in the player's hotbar, triggering a server crash and resulting in denial of service.

Scores

EPSS 0.0029
EPSS Percentile 52.2%

Classification

CWE
CWE-1284
Status draft

Affected Products (1)

pocketmine/pocketmine-mp < 4.18.1Packagist

Timeline

Published Dec 31, 2025
Tracked Since Feb 18, 2026