Executive brief
Cloudburst Network is a library used to handle network communications for software projects, including the Geyser Minecraft bridge. A flaw in how the library handles incoming connections allows a remote attacker to freeze the software's networking system. This results in a total service outage where the application becomes unresponsive to all users.
Technical details
A denial-of-service (DoS) vulnerability exists in Cloudburst Network (specifically the netty-transport-raknet component) due to missing bound checks during RakNet connection handling. By sending specially crafted packets, a remote, unauthenticated attacker can trigger a condition that stalls the Netty event loop. Because the event loop is responsible for processing I/O tasks, stalling it renders the entire network stack inoperable for the affected application. The vulnerability is classified as CWE-770 (Allocation of Resources Without Limits or Throttling). Users should update to version 1.0.0.CR3-20260417.085727-30 or later; Geyser users should update to Build #1114 or higher.
Affected products
- CloudburstMC Network (netty-transport-raknet) < 1.0.0.CR3-20260417.085727-30
Timeline
- 2026-05-12: advisory: GitHub Security Advisory published
- 2026-06-05: disclosed: NVD publication date