Vulnerability Description
CryptPad 2025.3.1 allows unbounded WebSocket frame flood. A remote, unauthenticated attacker can significantly degrade or deny service for all users of a CryptPad instance. Fixed in 2026.2.2.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Xwiki | Cryptpad | >= 2025.3.1, < 2026.2.2 |
Related Weaknesses (CWE)
References
- https://github.com/JohnPerifanis/cryptpad-cve-2025-51846-advisory/blob/main/READExploitThird Party Advisory
- https://github.com/cryptpad/cryptpad/pull/2239/changes/1e0c06ad8a0c5dab795f85f97Patch
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/Third Party Advisory
- https://www.cve.org/CVERecord?id=CVE-2025-51846Third Party Advisory
FAQ
What is CVE-2025-51846?
CVE-2025-51846 is a vulnerability with a CVSS score of 7.5 (HIGH). CryptPad 2025.3.1 allows unbounded WebSocket frame flood. A remote, unauthenticated attacker can significantly degrade or deny service for all users of a CryptPad instance. Fixed in 2026.2.2.
How severe is CVE-2025-51846?
CVE-2025-51846 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2025-51846?
Check the references section above for vendor advisories and patch information. Affected products include: Xwiki Cryptpad.