CVE-2025-71417: Pmmp Pocketmine-Mp
Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.
PocketMine-MP before 5.32.1 fails to validate uniqueness of pack UUIDs in ResourcePackClientResponsePacket STATUS_SEND_PACKS handling, allowing authenticated clients to trigger duplicate pack transmissions. Attackers can send multiple copies of valid pack UUIDs in a single packet to exhaust server memory and cause denial of service.
Affected products
- Pmmp Pocketmine-Mp: before 5.32.1 (fixed in 5.32.1)
Published 2026-09-09. Last modified 2026-10-08.