VYPR
Medium severity6.5NVD Advisory· Published Sep 9, 2026

CVE-2025-71417

CVE-2025-71417

Description

PocketMine-MP before 5.32.1 fails to validate uniqueness of pack UUIDs in ResourcePackClientResponsePacket STATUS_SEND_PACKS handling, allowing authenticated clients to trigger duplicate pack transmissions. Attackers can send multiple copies of valid pack UUIDs in a single packet to exhaust server memory and cause denial of service.

Affected products

2
  • Pmmp/Pocketmine Mpinferred2 versions
    <5.32.1+ 1 more
    • (no CPE)range: <5.32.1
    • (no CPE)range: <5.32.1

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.