CVE-2025-71417

PocketMine-MP before 5.32.1 fails to validate uniqueness of pack UUIDs in ResourcePackClientResponsePacket STATUS_SEND_PACKS handling, allowing authenticated clients to trigger duplicate pack transmissions. Attackers can send multiple copies of valid pack UUIDs in a single packet to exhaust server memory and cause denial of service.
Configurations

No configuration.

History

No history.

Information

Published : 2026-09-09 14:17

Updated : 2026-09-10 15:17


NVD link : CVE-2025-71417

Mitre link : CVE-2025-71417

CVE.ORG link : CVE-2025-71417


JSON object : View

Products Affected

No product.

CWE
CWE-20

Improper Input Validation