CVE-2026-42188 Details
Description
Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Edition. Prior to 2.9.3, a server-side request forgery (SSRF) vulnerability exists in Geyser’s handling of Bedrock player head texture data. By supplying a crafted Base64-encoded skin texture URL via the /give command, an attacker can cause the Minecraft server to issue arbitrary HTTP GET requests to attacker-controlled or internal endpoints. This occurs server-side, without proper URL validation, and can be triggered by a Bedrock client. This vulnerability is fixed in 2.9.3.
A server-side request forgery (SSRF) vulnerability has been identified in Geyser versions through 2.9.2. This vulnerability arises in Geyser's processing of Bedrock player head texture data. By sending a crafted Base64-encoded skin texture URL through the /give command, an attacker can manipulate the Minecraft server into making arbitrary HTTP GET requests to endpoints controlled by the attacker or to internal server endpoints. This exploitation occurs on the server side, without adequate URL validation, and can be initiated by a Bedrock client.
Users can update to Geyser version 2.9.3 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 13, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/GeyserMC/Geyser/security/advisories/GHSA-xcfg-fcr5-gw9r | CISA-ADP | ExploitVendor Advisory |
| https://github.com/GeyserMC/Geyser/security/advisories/GHSA-xcfg-fcr5-gw9r | [email protected] | ExploitVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-918 | Server-Side Request Forgery (SSRF) | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| geysermc geyser | < 2.9.3 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 25, 2026 | Initial Analysis | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 13, 2026 | CVE Modified | CISA-ADP |
| May 11, 2026 | New CVE Received | [email protected] |