CVE-2026-86198: Pmmp Pocketmine-Mp
Medium severity, CVSS 4.2. EPSS: 0.4% chance of exploitation in the next 30 days.
PocketMine-MP versions before 5.44.2 fail to properly validate multiple ResourcePackClientResponsePacket packets with STATUS_COMPLETED status during resource pack handling. Malicious clients can send batches of these packets to repeatedly trigger pre-spawn progression, creating duplicate Player objects and amplifying memory consumption and network traffic.
Affected products
- Pmmp Pocketmine-Mp: before 5.44.2 (fixed in 5.44.2)
Published 2026-09-09. Last modified 2026-09-10.