LOW
GeyserMC
CVE published 2026-05-11
CVE-2026-42188
The CVE record for CVE-2026-42188 was published on 2026-05-11T22:22:11.277Z and has not been modified since then. The NVD entry is currently Analyzed. This server-side request forgery (SSRF) vulnerability exists in Geyser's handling of Bedrock player head texture data prior to version 2.9.3. An attacker can cause the Minecraft server to issue arbitrary HTTP GET requests to attacker-controlled or internal [truncated]