CVE-2023-7332
Pocketmine-mp < 4.18.1 - Denial of Service
Title source: ruleDescription
PocketMine-MP versions prior to 4.18.1 contain an improper input validation vulnerability in inventory transaction handling. A remote attacker with a valid player session can request that the server drop more items than are available in the player's hotbar, triggering a server crash and resulting in denial of service.
References (4)
Scores
EPSS
0.0029
EPSS Percentile
52.2%
Classification
CWE
CWE-1284
Status
draft
Affected Products (1)
pocketmine/pocketmine-mp
< 4.18.1Packagist
Timeline
Published
Dec 31, 2025
Tracked Since
Feb 18, 2026