GHSA-8jq6-w5cg-wm45

    Dashboard / Vulnerabilities / GHSA-8jq6-w5cg-wm45

    GHSA-8jq6-w5cg-wm45

    Published: 11 Nov 2020Last Modified: 8 Sept 2026

    Summary: Exploitable inventory component chaining in PocketMine-MP

    Details: ### Impact Specially crafted `InventoryTransactionPacket`s sent by malicious clients were able to exploit the behaviour of `InventoryTransaction->findResultItem()` and cause it to take an abnormally long time to execute (causing an apparent server freeze). The affected code is intended to compact conflicting `InventoryActions` which are in the same `InventoryTransaction` by flattening them into a single action. When multiple pathways to a result existed, the complexity of this flattening became exponential. The problem was fixed by bailing when ambiguities are detected. **At the time of writing, this exploit is being used in the wild by attackers to deny service to servers.** ### Patches Upgrade to 3.15.4 or newer. ### Workarounds No practical workarounds are possible, short of backporting the fix or implementing checks in a plugin listening to `DataPacketReceiveEvent`. ### References c368ebb5e74632bc622534b37cd1447b97281e20 ### For more information If you have any questions or comments about this advisory: * Email us at [[email protected]](mailto:[email protected])

    Affected packages

    Package

    Name: pocketmine/pocketmine-mp

    Purl: pkg:composer/pocketmine/pocketmine-mp

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -3.15.4

    Affected versions

    3.0.0
    3.0.1
    3.0.10
    3.0.11
    3.0.12
    3.0.2
    3.0.3
    3.0.4
    3.0.5
    3.0.6
    3.0.7
    3.0.8
    3.0.9

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    GHSA-8jq6-w5cg-wm45 | CVE-DB