THREATOPS
THREAT OPSThreat News › [NVD] CVE-2022-51009 (HIGH 7.5) — PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin packets with invalid geometry JSON to trigger an unhandled RuntimeException, causing server crash.

[NVD] CVE-2022-51009 (HIGH 7.5) — PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin packets with invalid geometry JSON to trigger an unhandled RuntimeException, causing server crash.

mednvdPublished 2026-09-06

CVE-2022-51009 CVSS: 7.5 HIGH Published: 2026-09-06T12:17:15.073

PocketMine-MP before 4.7.2 fails to properly handle exceptions from the adhocore/json-comment library when parsing skin geometry data. Attackers can send login or skin packets with invalid geometry JSON to trigger an unhandled RuntimeException, causing server crash.

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2022-51009