CVE-2025-71417: Pmmp Pocketmine-Mp

Medium severity, CVSS 6.5. EPSS: 0.3% chance of exploitation in the next 30 days.

PocketMine-MP before 5.32.1 fails to validate uniqueness of pack UUIDs in ResourcePackClientResponsePacket STATUS_SEND_PACKS handling, allowing authenticated clients to trigger duplicate pack transmissions. Attackers can send multiple copies of valid pack UUIDs in a single packet to exhaust server memory and cause denial of service.

Affected products

  • Pmmp Pocketmine-Mp: before 5.32.1 (fixed in 5.32.1)

Published 2026-09-09. Last modified 2026-10-08.