Minecraft's vulnerability footprint centers on the game client and Bedrock Server products, where the durable signal reflects the complexity of deserializing untrusted network data, managing file paths in modding and content systems, and handling integer arithmetic in coordinate and inventory calculations. Treat this as a compact vendor profile; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Minecraft over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-33790CRITICAL The RebornCore library before 4.7.3 allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObject as part of reborncore.common.network.Extende | May 31, 2021 | 9.8 | 29 | NO | NO |
CVE-2023-33245HIGH Minecraft through 1.19 and 1.20 pre-releases before 7 (Java) allow arbitrary file overwrite, and possibly code execution, via crafted world data that contains a symlink. | May 30, 2023 | 8.8 | 27 | NO | NO |
CVE-2022-23884CRITICAL Mojang Bedrock Dedicated Server 1.18.2 is affected by an integer overflow leading to a bound check bypass caused by PurchaseReceiptPacket::_read (packet deserializer). | Mar 28, 2022 | 9.8 | 25 | NO | NO |
CVE-2021-35054HIGH Minecraft before 1.17.1, when online-mode=false is configured, allows path traversal for deletion of arbitrary JSON files. | Jul 20, 2021 | 7.5 | 25 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Minecraft.
Media articles that mention a CVE ID that affects a product developed by Minecraft — matched by CVE ID, not by vendor name.