CVE-2023-54395

medium

Description

PocketMine-MP versions before 4.12.5 contain a denial-of-service vulnerability in ModalFormResponsePacket processing that allows attackers to cause server resource exhaustion by sending large JSON payloads. Attackers can send numerous oversized modal form response packets to consume CPU time and prevent the server from processing legitimate connections.

References

https://www.vulncheck.com/advisories/pocketmine-mp-before-4.12.5-denial-of-service-via-modalformresponsepacket

https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-7m9r-rq9j-wmmh

https://github.com/pmmp/PocketMine-MP/commit/3baa5ab71214f96e6e7ab12cb9beef08118473b5

https://euvd.enisa.europa.eu/vulnerability/EUVD-2023-60625

Details

Source: Mitre, NVD

Published: 2026-09-09

Updated: 2026-10-08

Risk Information

CVSS v2

Base Score: 4

Vector: CVSS2#AV:N/AC:L/Au:S/C:N/I:N/A:P

Severity: Medium

CVSS v3

Base Score: 4.3

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L

Severity: Medium

CVSS v4

Base Score: 5.3

Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N

Severity: Medium

EPSS

EPSS: 0.0033