CVE-2025-71417 Overview
CVE-2025-71417 affects PocketMine-MP versions before 5.32.1, a server software implementation for Minecraft: Bedrock Edition. The vulnerability stems from missing uniqueness validation of pack UUIDs in the ResourcePackClientResponsePacket handler during STATUS_SEND_PACKS processing. Authenticated clients can submit multiple copies of valid pack UUIDs within a single packet, forcing the server to transmit duplicate resource packs. This behavior exhausts server memory and results in denial of service. The flaw is categorized under [CWE-20] Improper Input Validation.
Critical Impact
Authenticated attackers can exhaust server memory and crash PocketMine-MP servers by submitting crafted resource pack response packets.
Affected Products
- PocketMine-MP versions prior to 5.32.1
- Minecraft: Bedrock Edition server deployments using PocketMine-MP
- Any downstream distributions bundling vulnerable PocketMine-MP releases
Discovery Timeline
- 2026-09-09 - CVE-2025-71417 published to NVD
- 2026-09-09 - Last updated in NVD database
Technical Details for CVE-2025-71417
Vulnerability Analysis
PocketMine-MP negotiates resource packs with clients through a multi-stage handshake. During the STATUS_SEND_PACKS phase, the client submits a list of pack UUIDs it wants the server to transmit. The vulnerable code path processes each entry in the received list without deduplication. An attacker can populate the list with the same valid UUID many times, forcing the server to queue and transmit the same pack repeatedly. Each queued transmission consumes memory proportional to pack size multiplied by the number of duplicate entries, leading to memory exhaustion and server termination.
Root Cause
The root cause is improper input validation in the ResourcePackClientResponsePacket handler. The code accepts the client-supplied UUID list at face value and does not enforce uniqueness before scheduling pack transmissions. Because the packet is only received after authentication, the server implicitly trusts the requester and skips resource-usage limits on the request.
Attack Vector
Exploitation requires an authenticated session to a target PocketMine-MP server. The attacker joins the server through the normal login flow, then sends a single crafted ResourcePackClientResponsePacket containing many duplicate pack UUIDs. The server responds by transmitting each duplicate copy, and memory usage grows until the process runs out of memory or the host kills it. No user interaction on the server side is required.
No verified proof-of-concept code is publicly available. See the GitHub Security Advisory and the VulnCheck Advisory for DoS for the technical writeups.
Detection Methods for CVE-2025-71417
Indicators of Compromise
- Repeated ResourcePackClientResponsePacket messages containing the same pack UUID from a single session.
- Rapid growth in the PocketMine-MP process resident memory shortly after a client authenticates.
- Server termination or out-of-memory kills in the host system log correlated with resource pack negotiation traffic.
Detection Strategies
- Inspect PocketMine-MP debug and network logs for oversized pack request lists during the STATUS_SEND_PACKS phase.
- Correlate authentication events with abnormal outbound bandwidth spikes tied to resource pack transmission.
- Alert on repeated server restarts or crash-loop patterns that follow player connections.
Monitoring Recommendations
- Track process memory and file descriptor counts for the PocketMine-MP service and alert on abrupt increases.
- Enable verbose network logging for the resource pack subsystem in staging or exposed instances.
- Monitor per-client packet rates and pack request sizes to identify abusive sessions early.
How to Mitigate CVE-2025-71417
Immediate Actions Required
- Upgrade PocketMine-MP to version 5.32.1 or later on all exposed servers.
- Restrict server access to trusted allowlists until the patched version is deployed.
- Enforce resource limits (memory, restart policies) at the process supervisor level to contain crashes.
Patch Information
The maintainers addressed the issue in PocketMine-MP 5.32.1 by validating uniqueness of pack UUIDs in the ResourcePackClientResponsePacket handler. Refer to the GitHub Security Advisory GHSA-fqqv-56h5-f57g for the fix details and upgrade guidance.
Workarounds
- Disable or minimize the use of server-hosted resource packs until the patched version is applied.
- Deploy the server behind a proxy that rate-limits packets and terminates abusive sessions.
- Run PocketMine-MP under a process manager configured with strict memory ceilings and automatic restart on failure.
# Configuration example: enforce a memory ceiling with systemd
# /etc/systemd/system/pocketmine.service.d/limits.conf
[Service]
MemoryMax=2G
Restart=on-failure
RestartSec=5s
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
