CVE-2026-45290 PUBLISHED

Cloudburst Network has DoS in RakNet connection handling due to missing bound checks

Assigner: GitHub_M
Reserved: 11.05.2026 Published: 05.06.2026 Updated: 05.06.2026

Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to 1.0.0.CR3-20260417.085727-30 impacts publicly accessible software depending on the affected versions of Network and allows an attacker to exploit a vulnerability in Network to stall the netty event loop, rendering it inoperable. All consumers of the library should upgrade to at least version 1.0.0.CR3-20260417.085727-30. There are no known workarounds beyond updating the library.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 7.5

Product Status

Vendor CloudburstMC
Product Network
Versions
  • Version < 1.0.0.CR3-20260417.085727-30 is affected

References

Problem Types

  • CWE-770: Allocation of Resources Without Limits or Throttling CWE