CVE-2022-51014

high

Description

PocketMine-MP before 4.0.7 contains an unhandled exception vulnerability in the ModalFormResponsePacket handler when processing malformed JSON from clients. Attackers can send specially crafted form response packets with invalid JSON to trigger an uncaught InvalidArgumentException, causing server crashes.

References

https://www.vulncheck.com/advisories/pocketmine-mp-before-4.0.7-denial-of-service-via-json-decoding

https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-wjfq-88q2-r34j

https://github.com/pmmp/PocketMine-MP/commit/56fe71d939c38fe14e18a31a673a9331bcc0e4ca

https://euvd.enisa.europa.eu/vulnerability/EUVD-2022-56043

Details

Source: Mitre, NVD

Published: 2026-09-07

Updated: 2026-10-08

Risk Information

CVSS v2

Base Score: 6.8

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:N/A:C

Severity: Medium

CVSS v3

Base Score: 6.5

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Severity: Medium

CVSS v4

Base Score: 7.1

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Severity: High

EPSS

EPSS: 0.00508