{"id":"GHSA-8jq6-w5cg-wm45","summary":"Exploitable inventory component chaining in PocketMine-MP","details":"### Impact\nSpecially crafted `InventoryTransactionPacket`s sent by malicious clients were able to exploit the behaviour of `InventoryTransaction-\u003efindResultItem()` and cause it to take an abnormally long time to execute (causing an apparent server freeze).\n\nThe affected code is intended to compact conflicting `InventoryActions` which are in the same `InventoryTransaction` by flattening them into a single action. When multiple pathways to a result existed, the complexity of this flattening became exponential.\n\nThe problem was fixed by bailing when ambiguities are detected.\n\n**At the time of writing, this exploit is being used in the wild by attackers to deny service to servers.**\n\n### Patches\nUpgrade to 3.15.4 or newer.\n\n### Workarounds\nNo practical workarounds are possible, short of backporting the fix or implementing checks in a plugin listening to `DataPacketReceiveEvent`.\n\n### References\nc368ebb5e74632bc622534b37cd1447b97281e20\n\n### For more information\nIf you have any questions or comments about this advisory:\n* Email us at [team@pmmp.io](mailto:team@pmmp.io)","aliases":["CVE-2020-37277"],"modified":"2026-09-08T12:38:07.821798547Z","published":"2020-11-11T21:38:18Z","database_specific":{"cwe_ids":["CWE-400"],"severity":"HIGH","github_reviewed":true,"github_reviewed_at":"2020-11-11T21:38:07Z","nvd_published_at":null},"references":[{"type":"WEB","url":"https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-8jq6-w5cg-wm45"}],"affected":[{"package":{"name":"pocketmine/pocketmine-mp","ecosystem":"Packagist","purl":"pkg:composer/pocketmine/pocketmine-mp"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"3.15.4"}]}],"versions":["3.0.0","3.0.1","3.0.10","3.0.11","3.0.12","3.0.2","3.0.3","3.0.4","3.0.5","3.0.6","3.0.7","3.0.8","3.0.9","3.1.0","3.1.1","3.1.2","3.1.3","3.1.4","3.1.5","3.1.6","3.1.7","3.1.8","3.10.0","3.10.1","3.11.0","3.11.1","3.11.2","3.11.3","3.11.4","3.11.5","3.11.6","3.11.7","3.12.0","3.12.1","3.12.2","3.12.3","3.12.4","3.12.5","3.12.6","3.13.0","3.13.1","3.14.0","3.14.1","3.14.2","3.14.3","3.15.0","3.15.1","3.15.2","3.15.3","3.2.0","3.2.1","3.2.2","3.2.3","3.2.4","3.2.5","3.2.6","3.2.7","3.3.0","3.3.1","3.3.2","3.3.3","3.3.4","3.4.0","3.4.1","3.4.2","3.4.3","3.5.0","3.5.1","3.5.10","3.5.11","3.5.12","3.5.13","3.5.2","3.5.3","3.5.4","3.5.5","3.5.6","3.5.7","3.5.8","3.5.9","3.6.0","3.6.1","3.6.2","3.6.3","3.6.4","3.6.5","3.6.6","3.7.0","3.7.1","3.7.2","3.7.3","3.8.0","3.8.1","3.8.2","3.8.3","3.8.4","3.8.5","3.8.6","3.8.7","3.9.0","3.9.1","3.9.2","3.9.3","3.9.4","3.9.5","3.9.6","3.9.7","3.9.8"],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2020/11/GHSA-8jq6-w5cg-wm45/GHSA-8jq6-w5cg-wm45.json"}}],"schema_version":"1.9.0"}