CVE-2025-51846

CryptPad 2025.3.1 allows unbounded WebSocket frame flood. A remote, unauthenticated attacker can significantly degrade or deny service for all users of a CryptPad instance. Fixed in 2026.2.2.
Configurations

Configuration 1 (hide)

cpe:2.3:a:xwiki:cryptpad:*:*:*:*:*:*:*:*

History

04 May 2026, 16:52

Type Values Removed Values Added
CPE cpe:2.3:a:xwiki:cryptpad:*:*:*:*:*:*:*:*
First Time Xwiki cryptpad
Xwiki
References () https://github.com/JohnPerifanis/cryptpad-cve-2025-51846-advisory/blob/main/README.md - () https://github.com/JohnPerifanis/cryptpad-cve-2025-51846-advisory/blob/main/README.md - Exploit, Third Party Advisory
References () https://github.com/cryptpad/cryptpad/pull/2239/changes/1e0c06ad8a0c5dab795f85f9730ec2693320c62e - () https://github.com/cryptpad/cryptpad/pull/2239/changes/1e0c06ad8a0c5dab795f85f9730ec2693320c62e - Patch
References () https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-119-01.json - () https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-119-01.json - Third Party Advisory
References () https://www.cve.org/CVERecord?id=CVE-2025-51846 - () https://www.cve.org/CVERecord?id=CVE-2025-51846 - Third Party Advisory

30 Apr 2026, 17:20

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-30 17:16

Updated : 2026-06-17 09:35


NVD link : CVE-2025-51846

Mitre link : CVE-2025-51846

CVE.ORG link : CVE-2025-51846


JSON object : View

Products Affected

xwiki

  • cryptpad
CWE
CWE-770

Allocation of Resources Without Limits or Throttling