Vulnerability Description
Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Edition. Prior to 2.9.3, a server-side request forgery (SSRF) vulnerability exists in Geyser’s handling of Bedrock player head texture data. By supplying a crafted Base64-encoded skin texture URL via the /give command, an attacker can cause the Minecraft server to issue arbitrary HTTP GET requests to attacker-controlled or internal endpoints. This occurs server-side, without proper URL validation, and can be triggered by a Bedrock client. This vulnerability is fixed in 2.9.3.
CVSS Score
LOW
Related Weaknesses (CWE)
References
- https://github.com/GeyserMC/Geyser/security/advisories/GHSA-xcfg-fcr5-gw9r
- https://github.com/GeyserMC/Geyser/security/advisories/GHSA-xcfg-fcr5-gw9r
FAQ
What is CVE-2026-42188?
CVE-2026-42188 is a vulnerability with a CVSS score of 2.4 (LOW). Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Edition. Prior to 2.9.3, a server-side request forgery (SSRF) vulnerability exists in Geyser’s handling of Bedrock player head...
How severe is CVE-2026-42188?
CVE-2026-42188 has been rated LOW with a CVSS base score of 2.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-42188?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.