CVE-2025-71417
PocketMine-MP before 5.32.1 fails to validate uniqueness of pack UUIDs in ResourcePackClientResponsePacket STATUS_SEND_PACKS handling, allowing authenticated clients to trigger duplicate pack transmissions. Attackers can send multiple copies of valid pack UUIDs in a single packet to exhaust server memory and cause denial of service.
- Published Sep 9, 2026
- CVSS 7.1 high
- 0.3% chance of exploitation in the next 30 days (EPSS)
- A fix is available