CVE-2026-42188
בינונית 4.3
תיאור (מקור, אנגלית)
Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Edition. Prior to 2.9.3, a server-side request forgery (SSRF) vulnerability exists in Geyser’s handling of Bedrock player head texture data. By supplying a crafted Base64-encoded skin texture URL via the /give command, an attacker can cause the Minecraft server to issue arbitrary HTTP GET requests to attacker-controlled or internal endpoints. This occurs server-side, without proper URL validation, and can be triggered by a Bedrock client. This vulnerability is fixed in 2.9.3.
מדדים
- CVSS 3.1
-
4.3 (MEDIUM)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N - EPSS — סבירות ניצול
- 0% (אחוזון 000) נכון ל-29/9/2026
- CWE
- CWE-918
מוצרים מושפעים
geysermc: geyser
קישורים
- https://github.com/GeyserMC/Geyser/security/advisories/GHSA-xcfg-fcr5-gw9r ExploitVendor Advisory
- https://github.com/GeyserMC/Geyser/security/advisories/GHSA-xcfg-fcr5-gw9r ExploitVendor Advisory