HIGH 7.1 NVD
CVE-2021-48007
PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket position and rotation fields. Malicious clients can send crafted mov
PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket position and rotation fields. Malicious clients can send crafted movement packets with invalid floating-point values to crash servers through unhandled mathematical operations or prevent clients from rendering other players.
References
- https://github.com/pmmp/PocketMine-MP/commit/fb20bb38327b4c08ee3976640cd0dd547388a638
- https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-fm35-jgg3-3grx
- https://www.vulncheck.com/advisories/pocketmine-mp-before-3.18.1-denial-of-service-via-mov
This high severity vulnerability with a CVSS score of 7.1 was published on 2026-09-06 via NVD.
vulnfeed aggregates 10006 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.