{"id":"CVE-2024-58380","aliases":[],"url":"https://o3.security/vulnerability/CVE-2024-58380","summary":"PocketMine-MP versions before 5.11.2 contain a denial of service vulnerability in BookEditPacket handling that crashes the server when an invalid inventory slot value is provided. Attackers…","details":"PocketMine-MP versions before 5.11.2 contain a denial of service vulnerability in BookEditPacket handling that crashes the server when an invalid inventory slot value is provided. Attackers can send a crafted BookEditPacket with an inventory slot greater than 35 to trigger an unhandled exception and crash the server.","published":"2026-09-09T13:31:54.824Z","modified":"2026-09-09T13:31:54.824Z","cvss":{"score":6.5,"severity":"MEDIUM","vector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":{"url":"https://github.com/pmmp/PocketMine-MP/commit/47f011966092f275cc1b11f8de635e89fd9651a7","label":"pmmp/PocketMine-MP@47f0119"},"references":[{"type":"ADVISORY","url":"https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-xc7j-wj36-qjfr"},{"type":"FIX","url":"https://github.com/pmmp/PocketMine-MP/commit/47f011966092f275cc1b11f8de635e89fd9651a7"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/pocketmine-mp-before-5.11.2-denial-of-service-via-bookeditpacket"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-09T13:31:54.824Z"}}