CVE-2023-7332
pmmp PocketMine-MP
PocketMine-MP versions prior to 4.18.1 contain an improper input validation vulnerability in inventory transaction handling. A remote attacker with a valid player session can request that the server drop more items than are available in the player's hotbar, triggering a server crash and resulting in denial of service.
- CVSS
- 7.1
- EPSS
- 0.34% 27.0% percentile
- CISA KEV
- Not listed
- Published
- 2026.01.01