CVE-2025-51846: CryptPad unbounded WebSocket frame flood
Published Apr 30, 2026
·Updated
CryptPad 2025.3.1 allows unbounded WebSocket frame flood. A remote, unauthenticated attacker can significantly degrade or deny service for all users of a CryptPad instance. Fixed in 2026.2.2.
Affected Software
2 affected components
CryptPad CryptPad<2026.2.2
XWiki CryptPad>=2025.3.1<2026.2.2
Remediation
Event History
Apr 30, 2026
CVE Published
via MITRE·04:35 PM
Data Sourced
via MITRE·04:35 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·05:16 PM
RemedyDescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-51846?
CVE-2025-51846 is considered to have a significant impact as it allows for service degradation or denial for all users of a CryptPad instance.
2
How do I fix CVE-2025-51846?
To resolve CVE-2025-51846, upgrade CryptPad to version 2026.2.2 or later.
3
What vulnerability does CVE-2025-51846 address?
CVE-2025-51846 addresses an unbounded WebSocket frame flood vulnerability in CryptPad.
4
Who can exploit CVE-2025-51846?
CVE-2025-51846 can be exploited by a remote, unauthenticated attacker.
5
What versions of CryptPad are affected by CVE-2025-51846?
CryptPad versions prior to 2026.2.2 are affected by CVE-2025-51846.