---
id: CVE-2023-54396
title: >-
  PocketMine-MP versions before 4.8.1 fail to validate dye color IDs in banner
  NBT data during deserialization
summary: >-
  PocketMine-MP versions before 4.8.1 fail to validate dye color IDs in banner
  NBT data during deserialization. Attackers can provide invalid color values in
  inventory transactions or via commands to trigger undefined offset errors and
  cra…
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'
cwe:
  - CWE-129
vendor: pmmp
product: PocketMine-MP
affected:
  - PocketMine-MP < 4.8.1
published: '2026-09-09'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T20:20:21.673'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2023-54396'
references:
  - url: >-
      https://github.com/pmmp/PocketMine-MP/commit/08b9495bce2d65a6d1d3eeb76e484499a00765eb
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-wqqv-jcfr-9f5g
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/pocketmine-mp-before-4.8.1-server-crash-via-banner-nbt
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-09T14:10:39.674626Z'
ingestedAt: '2026-09-09T14:11:29.381Z'
epss: 0.00376
epssPercentile: 0.3149
---

## Overview

PocketMine-MP versions before 4.8.1 fail to validate dye color IDs in banner NBT data during deserialization. Attackers can provide invalid color values in inventory transactions or via commands to trigger undefined offset errors and crash the server.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
