Back to mods
CrashExploitFixer project artwork

Modrinth · Minecraft mod

CrashExploitFixer

This mod fixes a bunch of crash exploits discovered in Minecraft.

Choose a version Pick your version below, then grab the matching file.

Quick answer

Which CrashExploitFixer release should I use?

Updated 2 months ago
Latest stable file forge-2.0.0+1.20.4
Game version 1.19, 1.19.1, 1.19.2
Loader Forge

CrashExploitFixer forge-2.0.0+1.20.4 targets 1.19, 1.19.1, 1.19.2 with Forge. Do not install it on the client. It must be installed on the dedicated server. No extra mods listed for this file.

Where it goes

Is CrashExploitFixer required on the client, server, or both?

Do not install it on the client. It must be installed on the dedicated server.

Client Not supported
Dedicated server Required
Loader for this release Forge
Required install it here Optional supported, not mandatory Not supported do not install here Source doesn’t say do not assume

This file is marked server-only.

What else does CrashExploitFixer forge-2.0.0+1.20.4 need?

forge-2.0.0+1.20.4. Change the file and its required mods may change too.

No extra mods listed for this file

This file does not list any required mods. Do not add a library just because a different file uses it.

This file does not list any required or optional mods.

Before you install it

Add CrashExploitFixer without breaking your instance.

Built for CrashExploitFixer forge-2.0.0+1.20.4. Pick another file and the loader, install side or required mods may change.

  1. 01

    Stick to this file

    Use forge-2.0.0+1.20.4. It targets 1.19, 1.19.1, 1.19.2 with Forge; another release may have different loader, side or dependency requirements.

  2. 02

    Bring the mods it needs

    This file does not list any required mods. Do not add a library just because a different file uses it.

  3. 03

    Put it on the correct side

    Do not install it on the client. It must be installed on the dedicated server.

  4. 04

    Pick the file you checked

    Use the “Get this file” button beside forge-2.0.0+1.20.4. It opens that exact file at the source.

About this project

What does CrashExploitFixer add?

CrashExploitFixer

The mod currently patches three different exploits for all affected Minecraft versions from 1.14.4 to Latest!

Entity Selector NBT Stack Overflow

A stack overflow vulnerability in Minecraft versions 1.14.4 through the latest release at the time of writing allows
attackers to crash servers by abusing deeply nested NBT data inside entity selectors, causing recursive parsing in
TagParser to exhaust the JVM stack. While Minecraft 1.21.1 prevents unprivileged players from triggering the
issue through entity selectors, operators and creative-mode players can still reproduce the crash on unpatched servers.
Notably, PaperMC discovered and patched the underlying parser issue months earlier.

Blogpost from haykam: haykam.com

Excessive Network Object Allocation

A denial-of-service vulnerability affecting Minecraft networking allowed authenticated players to crash servers by
sending malicious packets that triggered excessive memory allocation during collection deserialization through
FriendlyByteBuf.readCollection, FriendlyByteBuf.readMap, or related methods. While the issue was exploitable
through a Fabric API packet and likely many modded packets across different loaders, NeoForge and Fabric patched the
issue for their most active versions (NeoForge: 1.21.1 and 26.1, Fabric: 1.20.1, 1.21.1, 1.21.11, 26.1, 26.2).
CrashExploitFixer patches the issue for all versions of Forge, NeoForge, and Fabric and is compatible with their fixes.

Many thanks to Paul for reporting this in private

Blogpost from NeoForge: neoforged.net

Translatable Component Expansion

A denial-of-service vulnerability affecting Minecraft 1.16 through 1.21.4 allowed attackers to craft recursively
expanding text components that could inflate into enormous strings during parsing, flattening, or calls such as
Component#getString(), leading to severe memory exhaustion and client or server soft-crashes. Newer research showed
that specially constructed hover-event payloads could trigger the issue without elevated permissions in vanilla
1.20.5–1.21.4. PaperMC had already protected against
this class of exploit for years, while modded environments remain especially vulnerable due to widespread use of
FriendlyByteBuf#readComponent() and related component deserialization paths in network packets.

Many thanks to Paul for reporting this in private

Project description from Modrinth.

Pick your setup

CrashExploitFixer by Minecraft version and loader

Choose the version and loader you play, then open the matching release.

67 available setups

Showing the newest 12 of 32 game versions. Older files are in the list below.

Check the dependencies, then try the file in a copied instance before changing a world you care about.

Recent files

CrashExploitFixer versions and loaders

9 of 9 releases match

Looking for an older file? The official Modrinth project page is in Resources.