Security Advisory

CVE-2023-7332

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2025-12-31 21:37:38
Last updated 2026-01-02 14:35:36
Assigner VulnCheck
State PUBLISHED

Description

PocketMine-MP versions prior to 4.18.1 contain an improper input validation vulnerability in inventory transaction handling. A remote attacker with a valid player session can request that the server drop more items than are available in the players hotbar, triggering a server crash and resulting in denial of service.