Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-86202

MEDIUM NVD
CVSS Score 4.3
Severity MEDIUM
Published Sep 09, 2026
Vendor unknown

Description

PocketMine-MP versions before 5.39.2 contain a network amplification vulnerability in ActorEventPacket handling that allows clients to trigger consuming animations for all visible players. Attackers can send crafted ActorEventPacket messages to spam animation events to other clients and waste server CPU and memory resources.

References