---
id: CVE-2026-86202
title: >-
  PocketMine-MP versions before 5.39.2 contain a network amplification
  vulnerability in ActorEventPacket handling that allows clients to trigger
  consuming animations for all visible players
summary: >-
  PocketMine-MP versions before 5.39.2 contain a network amplification
  vulnerability in ActorEventPacket handling that allows clients to trigger
  consuming animations for all visible players. Attackers can send crafted
  ActorEventPacket mess…
severity: medium
cvss: 4.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'
cwe:
  - CWE-406
vendor: pmmp
product: PocketMine-MP
affected:
  - PocketMine-MP < 5.39.2
published: '2026-09-09'
updated: '2026-09-09'
sourceUpdated: '2026-09-09T20:20:21.673'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-86202'
references:
  - url: >-
      https://github.com/pmmp/PocketMine-MP/commit/aeea1150a772a005b92bd418366f1b7cf1a91ab5
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-7hmv-4j2j-pp6f
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/pocketmine-mp-before-5.39.2-network-amplification-via-actoreventpacket
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-09T14:35:48.114658Z'
ingestedAt: '2026-09-09T14:11:29.380Z'
epss: 0.0026
epssPercentile: 0.17977
---

## Overview

PocketMine-MP versions before 5.39.2 contain a network amplification vulnerability in ActorEventPacket handling that allows clients to trigger consuming animations for all visible players. Attackers can send crafted ActorEventPacket messages to spam animation events to other clients and waste server CPU and memory resources.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
