CVE-2025-71417
Deferred Deferred - Pending Action

ResourcePack UUID Duplication Denial of Service in PocketMine-MP

Vulnerability report for CVE-2025-71417, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-10

Assigner: VulnCheck

Description

PocketMine-MP before 5.32.1 fails to validate uniqueness of pack UUIDs in ResourcePackClientResponsePacket STATUS_SEND_PACKS handling, allowing authenticated clients to trigger duplicate pack transmissions. Attackers can send multiple copies of valid pack UUIDs in a single packet to exhaust server memory and cause denial of service.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-10
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
pocketmine pocketmine-mp to 5.32.1 (exc)
pocketmine mp to 5.32.1 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-20 The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a denial-of-service (DoS) vulnerability in PocketMine-MP versions before 5.32.1. It occurs when the server fails to validate duplicate resource pack UUIDs in a client's request packet. Authenticated users can send multiple copies of the same valid pack UUID, causing the server to repeatedly transmit the same resource packs. This exhausts server memory and may crash the server.

Detection Guidance

Monitor server logs for repeated resource pack transmission requests from the same client. Check for unusually high memory usage or crashes in PocketMine-MP processes. Use network monitoring tools to detect multiple identical ResourcePackClientResponsePacket transmissions from authenticated clients.

Impact Analysis

If exploited, this vulnerability can cause your PocketMine-MP server to run out of memory and crash, resulting in downtime. It requires an authenticated client to trigger, so unauthorized users cannot exploit it directly. However, if compromised accounts exist, they could be used to attack your server.

Compliance Impact

This vulnerability primarily causes denial-of-service conditions by exhausting server memory through repeated resource pack transmissions. It does not directly impact data confidentiality or integrity, which are key focus areas for GDPR and HIPAA. However, prolonged downtime from a DoS attack could disrupt services handling personal or health data, potentially leading to compliance violations if systems fail to meet availability requirements under these regulations.

Mitigation Strategies

Upgrade PocketMine-MP to version 5.32.1 or later. Implement input validation to remove duplicate pack UUIDs in the STATUS_SEND_PACKS packet handling. Configure server to disconnect clients sending excessive duplicate requests.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2025-71417. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart