CVE-2023-54395: PocketMine-MP before 4.12.5 Denial of Service via ModalFormResponsePacket

Published Sep 9, 2026
·
Updated

PocketMine-MP versions before 4.12.5 contain a denial-of-service vulnerability in ModalFormResponsePacket processing that allows attackers to cause server resource exhaustion by sending large JSON payloads. Attackers can send numerous oversized modal form response packets to consume CPU time and prevent the server from processing legitimate connections.

Affected Software

1 affected component
PocketMine-MP<4.12.5

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade PocketMine-MP to a version that resolves this vulnerability.

    Fixed in 4.12.5
  2. Compensating control

    Mitigate ongoing attacks by rate-limiting or blocking traffic that sends oversized ModalFormResponsePacket/large JSON payloads to reduce CPU exhaustion until the server is upgraded to 4.12.5.

Event History

Sep 9, 2026
CVE Published
via MITRE·01:31 PM
Data Sourced
via MITRE·01:31 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker needs network access to the PocketMine-MP server and low-privileged access sufficient to send modal form response packets. No user interaction is required.

2

What is the operational impact of exploitation?

An attacker can repeatedly send oversized JSON payloads in modal form response packets, consuming CPU resources. This can prevent the server from processing legitimate connections.

3

Which deployments are affected?

PocketMine-MP versions before 4.12.5 are affected. The provided information does not identify any configuration prerequisite beyond processing ModalFormResponsePacket traffic.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203