Java Addon V10 Patched |top|

Last updated: December 2024. This article will be updated as new CVEs or patch bypasses are discovered.

Hypixel-style minigame server "BlockBash" had 47 servers running Java Addon v10 for custom loot tables. They delayed patching for 10 days due to plugin compatibility concerns. During that window, an attacker used the RMI exploit to steal their Redis credentials, wiping 3 months of player statistics. After patching (moving to "java addon v10 patched"), they had to rebuild their anti-cheat from scratch. java addon v10 patched