CVE-2026-86198EPSS p29.9%

CVE-2026-86198CVE-2026-86198

Description

PocketMine-MP versions before 5.44.2 fail to properly validate multiple ResourcePackClientResponsePacket packets with STATUS_COMPLETED status during resource pack handling. Malicious clients can send batches of these packets to repeatedly trigger pre-spawn progression, creating duplicate Player objects and amplifying memory consumption and network traffic.

Scoring

CVSS 4.2 ()
VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L
EPSS0.38% probability of exploitation · percentile 29.9% · 2026-10-05T12:00:23Z
Last modified2026-09-10
Sourced from NVD + FIRST.org EPSS. Curated for EU compliance use cases by Adam Lundqvist, Founder at SQUR.