CVE-2026-45291 Details
Description
Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.0.0.CR3-20260418.124334-32` impacts publicly accessible software depending on the affected versions of Network and allows an attacker to exploit a bug in Network to close the parent netty channel, rendering it inoperable. All consumers of the library should upgrade to at least version `1.0.0.CR3-20260418.124334-32`. There are no known workarounds beyond updating the library.
A vulnerability exists in Cloudburst Network versions prior to 1.0.0.CR3-20260418.124334-32. This vulnerability allows an attacker to exploit a bug in the Network component, used within Cloudburst projects, to close the parent Netty channel of publicly accessible software that relies on the affected version. This action renders the channel inoperable. All users of the library are advised to upgrade to version 1.0.0.CR3-20260418.124334-32 or later. Geyser users should update to the latest builds, which include the fix.
Users should upgrade to Cloudburst Network version 1.0.0.CR3-20260418.124334-32 or later. Geyser users should update to the latest builds, which contain the fix.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jun 5, 2026CISA-ADP
Assessed Jun 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/CloudburstMC/Network/security/advisories/GHSA-rh6x-g5c8-2rmf | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-20 | Improper Input Validation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Cloudburst Network | < 1.0.0.CR3-20260418.124334-32 |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 5, 2026 | New CVE Received | [email protected] |
Volerion