CVE-2023-54396
MEDIUM
NVD
CVSS Score
6.5
Severity
MEDIUM
Published
Sep 09, 2026
Vendor
unknown
Description
PocketMine-MP versions before 4.8.1 fail to validate dye color IDs in banner NBT data during deserialization. Attackers can provide invalid color values in inventory transactions or via commands to trigger undefined offset errors and crash the server.