Retour à la veille

CVE-2026-86198

Publié : 9 septembre 2026
Modifié : 9 septembre 2026
Lien officiel NVD
Score CVSS
4.2
MEDIUM

Description détaillée

PocketMine-MP versions before 5.44.2 fail to properly validate multiple ResourcePackClientResponsePacket packets with STATUS_COMPLETED status during resource pack handling. Malicious clients can send batches of these packets to repeatedly trigger pre-spawn progression, creating duplicate Player objects and amplifying memory consumption and network traffic.

Vecteur d'attaque (CVSS)

Vecteur brut :CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L

Références et Patchs