Junglewise Threat Intelligence

CVE-2026-45290: Cloudburst Network DoS in RakNet connection handling

CVE-2026-45290 · Severity: high · CVSS 7.5 · Published 2026-06-05

Technologies: CloudburstMC Network. Vendors: CloudburstMC.

Executive brief

Cloudburst Network is a library used to handle network communications for software projects, including the Geyser Minecraft bridge. A flaw in how the library handles incoming connections allows a remote attacker to freeze the software's networking system. This results in a total service outage where the application becomes unresponsive to all users.

Technical details

A denial-of-service (DoS) vulnerability exists in Cloudburst Network (specifically the netty-transport-raknet component) due to missing bound checks during RakNet connection handling. By sending specially crafted packets, a remote, unauthenticated attacker can trigger a condition that stalls the Netty event loop. Because the event loop is responsible for processing I/O tasks, stalling it renders the entire network stack inoperable for the affected application. The vulnerability is classified as CWE-770 (Allocation of Resources Without Limits or Throttling). Users should update to version 1.0.0.CR3-20260417.085727-30 or later; Geyser users should update to Build #1114 or higher.

Affected products

  • CloudburstMC Network (netty-transport-raknet) < 1.0.0.CR3-20260417.085727-30

Timeline

  • 2026-05-12: advisory: GitHub Security Advisory published
  • 2026-06-05: disclosed: NVD publication date

References

Related threats