Back to mods
CrashExploitFixer project artwork

CurseForge · Minecraft mod

CrashExploitFixer

This mod fixes a bunch of crash exploits discovered in Minecraft.

Choose a version Pick your version below, then grab the matching file.

Quick answer

Which CrashExploitFixer release matches 26.2 Quilt?

Updated last month
Best match for your filters CrashExploitFixer Fabric 2.0.0+26.1.2
Game version 26.1, 26.1.1, 26.1.2
Loader Fabric, Quilt

CrashExploitFixer Fabric 2.0.0+26.1.2 targets 26.1, 26.1.1, 26.1.2 with Fabric, Quilt. The project page does not say whether it belongs on the client. The project page does not say whether it belongs on the dedicated server. No extra mods listed for this file.

Where it goes

Is CrashExploitFixer required on the client, server, or both?

The project page does not say whether it belongs on the client. The project page does not say whether it belongs on the dedicated server.

Client Source doesn’t say
Dedicated server Source doesn’t say
Loader for this release Fabric, Quilt
Required install it here Optional supported, not mandatory Not supported do not install here Source doesn’t say do not assume

The source does not explicitly classify this release as client-only or server-only.

What else does CrashExploitFixer Fabric 2.0.0+26.1.2 need?

CrashExploitFixer Fabric 2.0.0+26.1.2 on 26.2 Quilt. Every mod below is checked against that same setup.

No extra mods listed for this file

This file does not list any required mods. Do not add a library just because a different file uses it.

This file does not list any required or optional mods.

Before you install it

Add CrashExploitFixer without breaking your instance.

Built for CrashExploitFixer Fabric 2.0.0+26.1.2 on 26.2 Quilt. Pick another file and the loader, install side or required mods may change.

  1. 01

    Stick to this file

    Use CrashExploitFixer Fabric 2.0.0+26.1.2. It targets 26.1, 26.1.1, 26.1.2 with Fabric, Quilt; another release may have different loader, side or dependency requirements.

  2. 02

    Bring the mods it needs

    This file does not list any required mods. Do not add a library just because a different file uses it.

  3. 03

    Put it on the correct side

    The project page does not say whether it belongs on the client. The project page does not say whether it belongs on the dedicated server.

  4. 04

    Pick the file you checked

    Use the “Get this file” button beside CrashExploitFixer Fabric 2.0.0+26.1.2. It opens that exact file at the source.

About this project

What does CrashExploitFixer add?

CrashExploitFixer

The mod currently patches three different exploits for all affected Minecraft versions from 1.14.4 to Latest!

Entity Selector NBT Stack Overflow

A stack overflow vulnerability in Minecraft versions 1.14.4 through the latest release at the time of writing allows attackers to crash servers by abusing deeply nested NBT data inside entity selectors, causing recursive parsing in TagParser to exhaust the JVM stack. While Minecraft 1.21.1 prevents unprivileged players from triggering the issue through entity selectors, operators and creative-mode players can still reproduce the crash on unpatched servers. Notably, PaperMC discovered and patched the underlying parser issue months earlier.

Blogpost from haykam: haykam.com

Excessive Network Object Allocation

A denial-of-service vulnerability affecting Minecraft networking allowed authenticated players to crash servers by sending malicious packets that triggered excessive memory allocation during collection deserialization through FriendlyByteBuf.readCollection, FriendlyByteBuf.readMap, or related methods. While the issue was exploitable through a Fabric API packet and likely many modded packets across different loaders, NeoForge and Fabric patched the issue for their most active versions (NeoForge: 1.21.1 and 26.1, Fabric: 1.20.1, 1.21.1, 1.21.11, 26.1, 26.2). CrashExploitFixer patches the issue for all versions of Forge, NeoForge, and Fabric and is compatible with their fixes.

Many thanks to Paul for reporting this in private

Blogpost from NeoForge: neoforged.net

Translatable Component Expansion

A denial-of-service vulnerability affecting Minecraft 1.16 through 1.21.4 allowed attackers to craft recursively expanding text components that could inflate into enormous strings during parsing, flattening, or calls such as Component#getString(), leading to severe memory exhaustion and client or server soft-crashes. Newer research showed that specially constructed hover-event payloads could trigger the issue without elevated permissions in vanilla 1.20.5–1.21.4. PaperMC had already protected against this class of exploit for years, while modded environments remain especially vulnerable due to widespread use of FriendlyByteBuf#readComponent() and related component deserialization paths in network packets.

Many thanks to Paul for reporting this in private

Project description from CurseForge.

Pick your setup

CrashExploitFixer by Minecraft version and loader

Choose the version and loader you play, then open the matching release.

165 available setups

Showing the newest 12 of 48 game versions. Older files are in the list below.

Check the dependencies, then try the file in a copied instance before changing a world you care about.

Recent files

CrashExploitFixer versions and loaders

1 of 33 releases match
Clear filters

Looking for an older file? The official CurseForge project page is in Resources.