{"id":"CVE-2026-86198","title":"PocketMine-MP versions before 5.44.2 fail to properly validate multiple ResourcePackClientResponsePacket packets with STATUS_COMPLETED status during resource pack handling","summary":"PocketMine-MP versions before 5.44.2 fail to properly validate multiple ResourcePackClientResponsePacket packets with STATUS_COMPLETED status during resource pack handling. Malicious clients can send batches of these packets to repeatedl…","severity":"medium","cvss":4.2,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:L","cwe":["CWE-837"],"vendor":"pmmp","product":"PocketMine-MP","affected":["PocketMine-MP < 5.44.2"],"published":"2026-09-09","updated":"2026-09-10","sourceUpdated":"2026-09-10T15:17:50.150","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-86198","references":[{"url":"https://github.com/pmmp/PocketMine-MP/commit/7a27894146a04964ab628ed9033140fdbf887ff3","label":"disclosure@vulncheck.com"},{"url":"https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-pg53-p7qp-65cv","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/pocketmine-mp-before-5.44.2-denial-of-service-via-resourcepackclientresponsepacket","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-10T14:18:48.064572Z"},"ingestedAt":"2026-09-14T12:27:58.923Z","epss":0.0028,"epssPercentile":0.2068,"slug":"CVE-2026-86198","body":"## Overview\n\nPocketMine-MP versions before 5.44.2 fail to properly validate multiple ResourcePackClientResponsePacket packets with STATUS_COMPLETED status during resource pack handling. Malicious clients can send batches of these packets to repeatedly trigger pre-spawn progression, creating duplicate Player objects and amplifying memory consumption and network traffic.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":23,"depthScoreParts":{"impact":23.1,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}