Impact
PocketMine-MP versions before 5.44.2 do not properly verify multiple ResourcePackClientResponsePacket packets with a STATUS_COMPLETED status. When a malicious client sends a batch of these packets, each one triggers pre‑spawn progression, resulting in the creation of duplicate Player objects. The duplication increases memory consumption and floods the network with extra traffic, effectively exhausting server resources and causing service disruption.
Affected Systems
All PocketMine‑MP servers running any release earlier than 5.44.2 are affected. The vulnerability is specific to the PocketMine‑MP product from the pmmp vendor.
Risk and Exploitability
The CVSS score of 2.3 reflects a low severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog, indicating no known widespread exploitation. Based on the description, the likely attack vector is a client that connects to the server and sends specially crafted packets; an attacker would need to maintain a connection to the vulnerable server to deliver the DoS payload. The risk to confidentiality, integrity, or availability beyond resource exhaustion is minimal, but the impact on availability can be significant for a busy multiplayer server.
OpenCVE Enrichment