CVE-2023-54395EPSS p23.9%
CVE-2023-54395CVE-2023-54395
Description
PocketMine-MP versions before 4.12.5 contain a denial-of-service vulnerability in ModalFormResponsePacket processing that allows attackers to cause server resource exhaustion by sending large JSON payloads. Attackers can send numerous oversized modal form response packets to consume CPU time and prevent the server from processing legitimate connections.
Scoring
| CVSS | 4.3 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:L |
| EPSS | 0.33% probability of exploitation · percentile 23.9% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-10 |