SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2023-54393

HIGH · CVSS 7.5 EPSS 0.35% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Versions of PocketMine-MP prior to 4.20.5 are vulnerable to a denial of service attack stemming from improper validation in the JsonMapper dependency, allowing attackers to crash the server by sending malformed JSON structures in the LoginPacket. Organizations using affected versions should prioritize patching to mitigate the risk of service disruption. This vulnerability poses a significant threat to server availability and should be addressed promptly by all users of PocketMine-MP.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
poc

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2023-54393
Severity
HIGH
CVSS
7.5
EPSS
0.35%

Original NVD Description

PocketMine-MP versions before 4.20.5 contain a denial of service vulnerability in LoginPacket JSON parsing due to improper validation in the JsonMapper dependency. Attackers can send malformed JSON structures in LoginPacket to crash the server.