CVE-2026-86202: PocketMine-MP before 5.39.2 Network Amplification via ActorEventPacket
PocketMine-MP versions before 5.39.2 contain a network amplification vulnerability in ActorEventPacket handling that allows clients to trigger consuming animations for all visible players. Attackers can send crafted ActorEventPacket messages to spam animation events to other clients and waste server CPU and memory resources.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
PocketMine-MPto a version that resolves this vulnerability.Fixed in 5.39.2
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
An attacker needs network access to the server and low-privileged access as a client. No user interaction is required.
Which deployments are affected?
PocketMine-MP versions before 5.39.2 are affected. The provided information does not identify any configuration prerequisite, so exposed servers running an affected version should be treated as vulnerable.
What is the practical impact on a server?
A malicious client can send crafted ActorEventPacket messages that cause consuming animations to be sent to all visible players. Repeated events can waste server CPU and memory resources and disrupt connected clients.
How can this be remediated?
Update PocketMine-MP to version 5.39.2 or later.