CVE-2026-86198
CVE-2026-86198 is a medium-severity vulnerability with a CVSS 3.x base score of 4.2. It is not currently listed as actively exploited by CISA, and its EPSS exploit-prediction score is low. The underlying weakness is classified as CWE-837.
Key facts
- Severity: Medium (CVSS 3.x base score 4.2)
- CVSS v4: 2.3
- EPSS exploit prediction: 0% (30th percentile)
- Actively exploited: Not listed in CISA KEV
- Weakness: CWE-837
- Published:
- Last modified:
Description
PocketMine-MP versions before 5.44.2 fail to properly validate multiple ResourcePackClientResponsePacket packets with STATUS_COMPLETED status during resource pack handling. Malicious clients can send batches of these packets to repeatedly trigger pre-spawn progression, creating duplicate Player objects and amplifying memory consumption and network traffic.
Frequently asked questions
- What is CVE-2026-86198?
- PocketMine-MP versions before 5.44.2 fail to properly validate multiple ResourcePackClientResponsePacket packets with STATUS_COMPLETED status during resource pack handling. Malicious clients can send batches of these packets to repeatedly trigger pre-spawn progression, creating duplicate Player objects and amplifying memory consumption and network traffic.
- How severe is CVE-2026-86198?
- CVE-2026-86198 has a CVSS 3.x base score of 4.2, rated medium severity. It is exploitable over network with high attack complexity, requires low privileges and no user interaction. Impact on confidentiality is none, integrity low, and availability low.
- Is CVE-2026-86198 being actively exploited?
- It is not currently listed in CISA's KEV catalog. Its EPSS exploit-prediction score is 0% (30th percentile), an estimate of the probability of exploitation in the next 30 days.
- How do I fix CVE-2026-86198?
- Review the linked vendor and NVD advisories for patched versions and mitigations, then upgrade or apply the recommended workaround.
- When was CVE-2026-86198 published?
- CVE-2026-86198 was published on 2026-09-09 and last updated on 2026-09-10.
References
- https://github.com/pmmp/PocketMine-MP/commit/7a27894146a04964ab628ed9033140fdbf887ff3
- https://github.com/pmmp/PocketMine-MP/security/advisories/GHSA-pg53-p7qp-65cv
- https://www.vulncheck.com/advisories/pocketmine-mp-before-5.44.2-denial-of-service-via-resourcepackclientresponsepacket
Other CWE-837 vulnerabilities
- CVE-2026-105850 — High (CVSS 8.8): Payload is a free and open source headless content management system. In @payloadcms/plugin-ecommerce versions before…
- CVE-2025-54315 — High (CVSS 7.1): The Matrix specification before 1.16 (i.e., with a room version before 12) lacks create event uniqueness.
- CVE-2024-11301 — Medium (CVSS 6.5): In lunary-ai/lunary before version 1.6.3, the application allows the creation of evaluators without enforcing a unique…
- CVE-2024-4629 — Medium (CVSS 6.5): A vulnerability was found in Keycloak. This flaw allows attackers to bypass brute force protection by exploiting the…
- CVE-2024-11717 — Medium (CVSS 6.3): Tokens in CTFd used for account activation and password resetting can be used interchangeably for these operations.…
- CVE-2026-45734 — Medium (CVSS 5.3): MyBB is free and open source forum software. Prior to 1.8.40, the built-in CAPTCHA does not consistently enforce…