CVE-2026-45289 Details
Description
CloudburstMC Protocol is a protocol library for Minecraft Bedrock Edition. Prior to version 3.0.0.Beta12-20260420.182526-15, CloudburstMC Protocol is partially missing validation for FULL type authentication tokens (Cloudburst/Protocol). This vulnerability impacts publicly accessible software depending on the affected versions of Protocol, specifically the EncryptionUtils methods to validate auth payloads for FULL type tokens. This issue has been patched in version 3.0.0.Beta12-20260420.182526-15.
A vulnerability exists in CloudburstMC Protocol for Minecraft Bedrock Edition, in versions prior to 3.0.0.Beta12-20260420.182526-15. The issue arises from a partial lack of validation for FULL type authentication tokens, specifically in the EncryptionUtils methods that validate authentication payloads. This vulnerability affects publicly accessible software that relies on the affected versions of the protocol.
Users of the CloudburstMC Protocol library should upgrade to version 3.0.0.Beta12-20260420.182526-15 or later. Geyser users can update to the latest builds, which include this fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 2, 2026CISA-ADP
Assessed Jun 3, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/CloudburstMC/Protocol/security/advisories/GHSA-g2fr-c75x-4hf9 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| CloudburstMC Protocol | < 3.0.0.Beta12-20260420.182526-15 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 22, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 2, 2026 | New CVE Received | [email protected] |
Volerion