CryptPad 2025.3.1 allows unbounded WebSocket frame flood. A remote, unauthenticated attacker can significantly degrade or deny service for all users of a CryptPad instance. Fixed in 2026.2.2.
References
| Link | Resource |
|---|---|
| https://github.com/JohnPerifanis/cryptpad-cve-2025-51846-advisory/blob/main/README.md | Exploit Third Party Advisory |
| https://github.com/cryptpad/cryptpad/pull/2239/changes/1e0c06ad8a0c5dab795f85f9730ec2693320c62e | Patch |
| https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-119-01.json | Third Party Advisory |
| https://www.cve.org/CVERecord?id=CVE-2025-51846 | Third Party Advisory |
Configurations
History
No history.
Information
Published : 2026-04-30 17:16
Updated : 2026-06-17 09:35
NVD link : CVE-2025-51846
Mitre link : CVE-2025-51846
CVE.ORG link : CVE-2025-51846
JSON object : View
Products Affected
xwiki
- cryptpad
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
