CVE-2022-51008

    Dashboard / Vulnerabilities / CVE-2022-51008

    CVE-2022-51008

    Published: 6 Sept 2026Last Modified: 10 Sept 2026

    Summary: PocketMine-MP before 4.12.3 Denial of Service via Unauthenticated Sessions

    Details: PocketMine-MP before 4.12.3 fails to limit unauthenticated sessions, allowing attackers to exhaust player slots by creating sessions without sending LoginPacket. Attackers can flood the server with unauthenticated connections that occupy max-player slots, preventing legitimate players from joining.

    Affected packages

    Package

    Name:

    Purl:

    Affected ranges

    Type: GIT

    Events:

    Introduced- 468faa464b2bc5c97f23fafbb71ea61035f6f218

    Affected versions

    4.12.2
    4.12.1
    4.12.0

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    CVE-2022-51008 | CVE-DB