CVE-2020-37277
MEDIUM
NVD
CVSS Score
6.5
Severity
MEDIUM
Published
Sep 06, 2026
Vendor
unknown
Description
PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send specially crafted InventoryTransactionPackets with multiple conflicting pathways to cause exponential processing complexity, freezing the server.