CryptPad 2025.3.1 allows unbounded WebSocket frame flood. A remote, unauthenticated attacker can significantly degrade or deny service for all users of a CryptPad instance. Fixed in 2026.2.2.
References
| Link | Resource |
|---|---|
| https://github.com/JohnPerifanis/cryptpad-cve-2025-51846-advisory/blob/main/README.md | Exploit Third Party Advisory |
| https://github.com/cryptpad/cryptpad/pull/2239/changes/1e0c06ad8a0c5dab795f85f9730ec2693320c62e | Patch |
| https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-119-01.json | Third Party Advisory |
| https://www.cve.org/CVERecord?id=CVE-2025-51846 | Third Party Advisory |
Configurations
History
04 May 2026, 16:52
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:xwiki:cryptpad:*:*:*:*:*:*:*:* | |
| First Time |
Xwiki cryptpad
Xwiki |
|
| References | () https://github.com/JohnPerifanis/cryptpad-cve-2025-51846-advisory/blob/main/README.md - Exploit, Third Party Advisory | |
| References | () https://github.com/cryptpad/cryptpad/pull/2239/changes/1e0c06ad8a0c5dab795f85f9730ec2693320c62e - Patch | |
| References | () https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-119-01.json - Third Party Advisory | |
| References | () https://www.cve.org/CVERecord?id=CVE-2025-51846 - Third Party Advisory |
30 Apr 2026, 17:20
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-30 17:16
Updated : 2026-06-17 09:35
NVD link : CVE-2025-51846
Mitre link : CVE-2025-51846
CVE.ORG link : CVE-2025-51846
JSON object : View
Products Affected
xwiki
- cryptpad
CWE
CWE-770
Allocation of Resources Without Limits or Throttling
