Medium severity6.5NVD Advisory· Published Sep 9, 2026
CVE-2025-71417
CVE-2025-71417
Description
PocketMine-MP before 5.32.1 fails to validate uniqueness of pack UUIDs in ResourcePackClientResponsePacket STATUS_SEND_PACKS handling, allowing authenticated clients to trigger duplicate pack transmissions. Attackers can send multiple copies of valid pack UUIDs in a single packet to exhaust server memory and cause denial of service.
Affected products
2<5.32.1+ 1 more
- (no CPE)range: <5.32.1
- (no CPE)range: <5.32.1
Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.