{"id":"CVE-2022-51012","title":"PocketMine-MP versions before 4.2.9 fail to properly validate NBT data types during deserialization of inventory transaction packets from clients","summary":"PocketMine-MP versions before 4.2.9 fail to properly validate NBT data types during deserialization of inventory transaction packets from clients. Attackers can send crafted inventory transactions with malformed NBT tags to trigger serve…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H","cwe":["CWE-20"],"vendor":"pmmp","product":"PocketMine-MP","affected":["PocketMine-MP < 4.2.9"],"published":"2026-09-07","updated":"2026-09-08","sourceUpdated":"2026-09-08T19:59:42.500","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2022-51012","references":[{"url":"https://github.com/pmmp/PocketMine-MP/commit/5a98b08ee8dc8ff14862cd83d2e4af9d212fefc2","label":"disclosure@vulncheck.com"},{"url":"https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-g5rr-p69h-7v3g","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/pocketmine-mp-before-4.2.9-denial-of-service-via-nbt-deserialization","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"epss":0.00508,"epssPercentile":0.42234,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-08T12:51:35.267702Z"},"ingestedAt":"2026-09-08T15:33:26.976Z","slug":"CVE-2022-51012","body":"## Overview\n\nPocketMine-MP versions before 4.2.9 fail to properly validate NBT data types during deserialization of inventory transaction packets from clients. Attackers can send crafted inventory transactions with malformed NBT tags to trigger server crashes and cause denial of service.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}