CVE-2026-45290 Details
Description
Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.0.0.CR3-20260417.085727-30` impacts publicly accessible software depending on the affected versions of Network and allows an attacker to exploit a vulnerability in Network to stall the netty event loop, rendering it inoperable. All consumers of the library should upgrade to at least version `1.0.0.CR3-20260417.085727-30`. There are no known workarounds beyond updating the library.
A denial-of-service vulnerability has been identified in Cloudburst Network versions prior to 1.0.0.CR3-20260417.085727-30. This vulnerability affects publicly accessible software that relies on the affected version of the Network component. It allows an attacker to exploit a flaw in the Network library to disrupt the Netty event loop, causing it to become unresponsive and inoperable. Geyser users should note that the latest builds (Build #1114+) contain the necessary fix.
Users of Cloudburst Network should upgrade to version 1.0.0.CR3-20260417.085727-30 or later. Geyser users can update to the latest builds, which include the fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 5, 2026CISA-ADP
Assessed Jun 9, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/CloudburstMC/Network/security/advisories/GHSA-7x5h-rg5x-9gf3 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Cloudburst Network | < 1.0.0.CR3-20260417.085727-30 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 5, 2026 | New CVE Received | [email protected] |
Volerion