Improper Enforcement of a Single, Unique Action Affecting pocketmine/pocketmine-mp package, versions <5.44.2


Severity

Recommended
0.0
low
0
10

CVSS assessment by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.38% (30th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-PHP-POCKETMINEPOCKETMINEMP-20158591
  • published27 Sept 2026
  • disclosed9 Sept 2026
  • creditUnknown

Introduced: 9 Sep 2026

NewCVE-2026-86198  (opens in a new tab)
CWE-837  (opens in a new tab)

How to fix?

Upgrade pocketmine/pocketmine-mp to version 5.44.2 or higher.

Overview

pocketmine/pocketmine-mp is a highly customisable, open source server software for Minecraft: Bedrock Edition written in PHP

Affected versions of this package are vulnerable to Improper Enforcement of a Single, Unique Action in the handling of ResourcePackClientResponsePacket packets with STATUS_COMPLETED status. An attacker can cause excessive memory consumption and increased network traffic by sending batches of these packets to repeatedly trigger pre-spawn progression, resulting in the creation of duplicate Player objects.

CVSS Base Scores

version 4.0
version 3.1