CurseForge · Minecraft mod
CrashExploitFixer
This mod fixes a bunch of crash exploits discovered in Minecraft.
Quick answer
Which CrashExploitFixer release matches 26.1.2 Fabric?
CrashExploitFixer Fabric 2.0.0+26.1.2 targets 26.1, 26.1.1, 26.1.2 with Fabric, Quilt. The project page does not say whether it belongs on the client. The project page does not say whether it belongs on the dedicated server. No extra mods listed for this file.
Where it goes
Is CrashExploitFixer required on the client, server, or both?
The project page does not say whether it belongs on the client. The project page does not say whether it belongs on the dedicated server.
The source does not explicitly classify this release as client-only or server-only.
What else does CrashExploitFixer Fabric 2.0.0+26.1.2 need?
CrashExploitFixer Fabric 2.0.0+26.1.2 on 26.1.2 Fabric. Every mod below is checked against that same setup.
This file does not list any required mods. Do not add a library just because a different file uses it.
This file does not list any required or optional mods.
Before you install it
Add CrashExploitFixer without breaking your instance.
Built for CrashExploitFixer Fabric 2.0.0+26.1.2 on 26.1.2 Fabric. Pick another file and the loader, install side or required mods may change.
- 01
Stick to this file
Use CrashExploitFixer Fabric 2.0.0+26.1.2. It targets 26.1, 26.1.1, 26.1.2 with Fabric, Quilt; another release may have different loader, side or dependency requirements.
- 02
Bring the mods it needs
This file does not list any required mods. Do not add a library just because a different file uses it.
- 03
Put it on the correct side
The project page does not say whether it belongs on the client. The project page does not say whether it belongs on the dedicated server.
- 04
Pick the file you checked
Use the “Get this file” button beside CrashExploitFixer Fabric 2.0.0+26.1.2. It opens that exact file at the source.
About this project
What does CrashExploitFixer add?
CrashExploitFixer
The mod currently patches three different exploits for all affected Minecraft versions from 1.14.4 to Latest!
Entity Selector NBT Stack Overflow
A stack overflow vulnerability in Minecraft versions 1.14.4 through the latest release at the time of writing allows attackers to crash servers by abusing deeply nested NBT data inside entity selectors, causing recursive parsing in TagParser to exhaust the JVM stack. While Minecraft 1.21.1 prevents unprivileged players from triggering the issue through entity selectors, operators and creative-mode players can still reproduce the crash on unpatched servers. Notably, PaperMC discovered and patched the underlying parser issue months earlier.
Blogpost from haykam: haykam.com
Excessive Network Object Allocation
A denial-of-service vulnerability affecting Minecraft networking allowed authenticated players to crash servers by sending malicious packets that triggered excessive memory allocation during collection deserialization through FriendlyByteBuf.readCollection, FriendlyByteBuf.readMap, or related methods. While the issue was exploitable through a Fabric API packet and likely many modded packets across different loaders, NeoForge and Fabric patched the issue for their most active versions (NeoForge: 1.21.1 and 26.1, Fabric: 1.20.1, 1.21.1, 1.21.11, 26.1, 26.2). CrashExploitFixer patches the issue for all versions of Forge, NeoForge, and Fabric and is compatible with their fixes.
Many thanks to Paul for reporting this in private
Blogpost from NeoForge: neoforged.net
Translatable Component Expansion
A denial-of-service vulnerability affecting Minecraft 1.16 through 1.21.4 allowed attackers to craft recursively expanding text components that could inflate into enormous strings during parsing, flattening, or calls such as Component#getString(), leading to severe memory exhaustion and client or server soft-crashes. Newer research showed that specially constructed hover-event payloads could trigger the issue without elevated permissions in vanilla 1.20.5–1.21.4. PaperMC had already protected against this class of exploit for years, while modded environments remain especially vulnerable due to widespread use of FriendlyByteBuf#readComponent() and related component deserialization paths in network packets.
Many thanks to Paul for reporting this in private
Project description from CurseForge.
Pick your setup
CrashExploitFixer by Minecraft version and loader
Choose the version and loader you play, then open the matching release.
26.2
4 loader builds26.1.2
4 loader builds26.1.1
4 loader builds26.1-snapshot
3 loader builds26.1-rc-3
3 loader builds26.1
4 loader builds1.21.11-rc2
3 loader builds1.21.11
4 loader builds1.21.10
4 loader builds1.21.9
4 loader builds1.21.8
4 loader buildsShowing the newest 12 of 48 game versions. Older files are in the list below.
Check the dependencies, then try the file in a copied instance before changing a world you care about.
Recent files
CrashExploitFixer versions and loaders
CrashExploitFixer Fabric 2.0.0+26.1.2
crashexploitfixer-fabric-2.0.0+26.1.2.jar
10 May 2026
CrashExploitFixer fabric-1.2.0+26.1-rc-3
crashexploitfixer-fabric-1.2.0+26.1-rc-3.jar
23 Mar 2026
Looking for an older file? The official CurseForge project page is in Resources.