CYBER CODE RED

Get real-time updates on Telegram

P4Verified

CVE-2025-71418: PocketMine-MP 0 to before 5.25.2

CVE-2025-71418. CVSS 3.1 base score 5.3 (MEDIUM, Vendor/CNA). EPSS 0.00401 (percentile 0.32104), scored 2026-10-06.

Affected technology

PocketMine-MP · 0 to before 5.25.2
pmmp

Description’s affected range: versions before 5.25.2 fail to limit the explode() function in packet parsing

Component: Not specified by the source
Function: in

Attack conditions (Vendor/CNA, CVSS 4.0): Network (remote) · No privileges required · No user interaction required

What an attacker can do

Attackers can send crafted packets with excessive delimiters to consume CPU and memory through sign editing, JWT parsing, and command parsing endpoints. Vendor/CNA’s CVSS 4.0 assessment (base score 6.9/10) rates confidentiality and integrity impact as none; availability impact as low.

Published

CWE
CWE-400
CCR priority
21.3 /100 (P4)
CVSS 3.1
5.3 /10 · CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L · Vendor/CNA
EPSS
0.00401 · percentile 0.32203 · 2026-10-08
KEV
no

Provenance

Stable permalink: https://cybercodered.org/item/cve-cve-2025-71418.html