THREATOPS
THREAT OPSThreat News › [NVD] CVE-2020-37277 (MEDIUM 6.5) — PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send specially crafted InventoryTransactionPackets with multiple conflicting pathways to cause exponential process

[NVD] CVE-2020-37277 (MEDIUM 6.5) — PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send specially crafted InventoryTransactionPackets with multiple conflicting pathways to cause exponential process

mednvdPublished 2026-09-06

CVE-2020-37277 CVSS: 6.5 MEDIUM Published: 2026-09-06T12:17:13.547

PocketMine-MP versions before 3.15.4 contain a denial of service vulnerability in the InventoryTransaction component's findResultItem() method. Malicious clients can send specially crafted InventoryTransactionPackets with multiple conflicting pathways to cause exponential processing complexity, freezing the server.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2020-37277