PT-2026-37252 · Geyser · Geyser

Mugi-Sec

·

Published

2026-05-05

·

Updated

2026-05-12

·

CVE-2026-42188

CVSS v3.1

2.4

Low

VectorAV:N/AC:L/PR:H/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Geyser versions prior to 2.9.3
Description A server-side request forgery (SSRF) exists in the handling of Bedrock player head texture data. By supplying a crafted Base64-encoded skin texture URL via the '/give' command, an attacker can cause the Minecraft server to issue arbitrary HTTP GET requests to internal or attacker-controlled endpoints. This occurs because the URL contained in the textures.SKIN.url field is not sufficiently validated when Geyser processes the Base64-encoded JSON value for custom player heads using the minecraft:profile NBT structure. This blind SSRF can be used for internal network probing, cloud metadata access attempts, and IP address disclosure of the Minecraft server.
Recommendations Update to version 2.9.3.

Exploit

Fix

SSRF

Weakness Enumeration

Related Identifiers

CVE-2026-42188
GHSA-XCFG-FCR5-GW9R

Affected Products

Geyser