Description
PocketMine-MP versions before 5.44.2 fail to properly validate multiple ResourcePackClientResponsePacket packets with STATUS_COMPLETED status during resource pack handling. Malicious clients can send batches of these packets to repeatedly trigger pre-spawn progression, creating duplicate Player objects and amplifying memory consumption and network traffic.
Published: 2026-09-09
Score: 2.3 Low
EPSS: < 1% Very Low
KEV: No
Impact: Denial of Service
Action: Apply Patch
AI Analysis

Impact

PocketMine-MP versions before 5.44.2 do not properly verify multiple ResourcePackClientResponsePacket packets with a STATUS_COMPLETED status. When a malicious client sends a batch of these packets, each one triggers pre‑spawn progression, resulting in the creation of duplicate Player objects. The duplication increases memory consumption and floods the network with extra traffic, effectively exhausting server resources and causing service disruption.

Affected Systems

All PocketMine‑MP servers running any release earlier than 5.44.2 are affected. The vulnerability is specific to the PocketMine‑MP product from the pmmp vendor.

Risk and Exploitability

The CVSS score of 2.3 reflects a low severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation. Based on the description, the likely attack vector is a client that connects to the server and sends specially crafted packets; an attacker would need to maintain a connection to the vulnerable server to deliver the DoS payload. The risk to confidentiality, integrity, or availability beyond resource exhaustion is minimal, but the impact on availability can be significant for a busy multiplayer server.

Generated by OpenCVE AI on September 9, 2026 at 15:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade PocketMine‑MP to version 5.44.2 or later, which includes the packet validation fix.
  • After applying the update, restart the server to ensure the new code is loaded.
  • Implement network‑level rate limiting or firewall rules to restrict the rate of ResourcePackClientResponsePacket traffic from untrusted clients to reduce the potential impact of any future similar issues.

Generated by OpenCVE AI on September 9, 2026 at 15:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
First Time appeared Pmmp
Pmmp pocketmine-mp
Vendors & Products Pmmp
Pmmp pocketmine-mp

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 09 Sep 2026 13:45:00 +0000

Type Values Removed Values Added
Description PocketMine-MP versions before 5.44.2 fail to properly validate multiple ResourcePackClientResponsePacket packets with STATUS_COMPLETED status during resource pack handling. Malicious clients can send batches of these packets to repeatedly trigger pre-spawn progression, creating duplicate Player objects and amplifying memory consumption and network traffic.
Title PocketMine-MP before 5.44.2 Denial of Service via ResourcePackClientResponsePacket
Weaknesses CWE-837
References
Metrics cvssV3_1

{'score': 4.2, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L'}

cvssV4_0

{'score': 2.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Pmmp Pocketmine-mp
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-09-10T14:58:07.124Z

Reserved: 2026-09-05T11:52:36.821Z

Link: CVE-2026-86198

cve-icon Vulnrichment

Updated: 2026-09-10T14:18:48.839Z

cve-icon NVD

Status : Deferred

Published: 2026-09-09T14:17:20.837

Modified: 2026-09-10T15:17:50.150

Link: CVE-2026-86198

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T16:30:17Z

Weaknesses
  • CWE-837

    Improper Enforcement of a Single, Unique Action