PocketMine-MP before 5.32.1 fails to validate uniqueness of pack UUIDs in ResourcePackClientResponsePacket STATUS_SEND_PACKS handling, allowing authenticated clients to trigger duplicate pack transmissions. Attackers can send multiple copies of valid pack UUIDs in a single packet to exhaust server memory and cause denial of service.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-09 14:17
Updated : 2026-09-10 15:17
NVD link : CVE-2025-71417
Mitre link : CVE-2025-71417
CVE.ORG link : CVE-2025-71417
JSON object : View
Products Affected
No product.
CWE
CWE-20
Improper Input Validation
