CVE-2021-48007 HIGH

CVE-2021-48007: PocketMine-MP before 3.18.1 Denial of Service via MovePlayerPacket

Vendor Pmmp
Product PocketMine-MP
Weakness CWE-20 · Input validation
Published September 6, 2026
Last update September 9, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality —
Integrity —

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

PocketMine-MP versions before 3.18.1 fail to validate NaN or INF values in MovePlayerPacket position and rotation fields. Malicious clients can send crafted movement packets with invalid floating-point values to crash servers through unhandled mathematical operations or prevent clients from rendering other players.

Key dates

02Disclosure timeline

September 6, 2026 CVE published
September 9, 2026 Record updated

Related vulnerabilities

04Related CVE