CVE-2025-51846
CryptPad unbounded WebSocket frame flood
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
CryptPad 2025.3.1 allows unbounded WebSocket frame flood. A remote, unauthenticated attacker can significantly degrade or deny service for all users of a CryptPad instance. Fixed in 2026.2.2.
| CWE | CWE-770 |
| Vendor | cryptpad |
| Product | cryptpad |
| Published | Apr 30, 2026 |
Stay Ahead of the Next One
Get instant alerts for cryptpad cryptpad
Be the first to know when new high vulnerabilities affecting cryptpad cryptpad are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected Versions
CryptPad / CryptPad
2025.3.1 < 2026.2.2
References
github.com: https://github.com/cryptpad/cryptpad/pull/2239/changes/1e0c06ad8a0c5dab795f85f9730ec2693320c62e cve.org: https://www.cve.org/CVERecord?id=CVE-2025-51846 raw.githubusercontent.com: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/IT/white/2026/va-26-119-01.json github.com: https://github.com/JohnPerifanis/cryptpad-cve-2025-51846-advisory/blob/main/README.md
Credits
John Perifanis, Unisystems