CVE-2026-86200
MEDIUMDescription
PocketMine-MP versions before 5.42.1 contain a denial of service vulnerability in the LoginPacket handler that allows remote attackers to flood warning messages by injecting numerous junk properties into the clientData JWT. Attackers can craft malicious login packets with excessive unknown properties to waste server CPU time and degrade performance.
Is your site exposed to CVE-2026-86200?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2026-86200? +
How severe is CVE-2026-86200? +
How do I check if I'm vulnerable to CVE-2026-86200? +
Related Vulnerabilities
Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the logging …
SuiteCRM is an open-source Customer Relationship Management (CRM) software application. Prior to versions 7.14.4 and 8.6.1, a deprecated v4 API …
Suricata is a network Intrusion Detection System, Intrusion Prevention System and Network Security Monitoring engine. Prior to version 7.0.8, DNS …
If an unauthenticated user sends a large amount of data to the Stork UI, it may cause memory and disk …
A vulnerability was found in python-glance-store. The issue occurs when the package logs the access_key for the glance-store when the …
Open OnDemand is an open-source HPC portal. Users can flood logs by interacting with the shell app and generating many …