---
id: CVE-2022-51012
title: >-
  PocketMine-MP versions before 4.2.9 fail to properly validate NBT data types
  during deserialization of inventory transaction packets from clients
summary: >-
  PocketMine-MP versions before 4.2.9 fail to properly validate NBT data types
  during deserialization of inventory transaction packets from clients.
  Attackers can send crafted inventory transactions with malformed NBT tags to
  trigger serve…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-20
vendor: pmmp
product: PocketMine-MP
affected:
  - PocketMine-MP < 4.2.9
published: '2026-09-07'
updated: '2026-09-08'
sourceUpdated: '2026-09-08T19:59:42.500'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2022-51012'
references:
  - url: >-
      https://github.com/pmmp/PocketMine-MP/commit/5a98b08ee8dc8ff14862cd83d2e4af9d212fefc2
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-g5rr-p69h-7v3g
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/pocketmine-mp-before-4.2.9-denial-of-service-via-nbt-deserialization
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
epss: 0.00508
epssPercentile: 0.4079
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-08T12:51:35.267702Z'
ingestedAt: '2026-09-08T15:33:26.976Z'
---

## Overview

PocketMine-MP versions before 4.2.9 fail to properly validate NBT data types during deserialization of inventory transaction packets from clients. Attackers can send crafted inventory transactions with malformed NBT tags to trigger server crashes and cause denial of service.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
