Vulnerability Details CVE-2025-51846
CryptPad 2025.3.1 allows unbounded WebSocket frame flood. A remote, unauthenticated attacker can significantly degrade or deny service for all users of a CryptPad instance. Fixed in 2026.2.2.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 72.7%
CVSS Severity
CVSS v3 Score 7.5
Products affected by CVE-2025-51846
-
cpe:2.3:a:xwiki:cryptpad:2025.3.1
-
cpe:2.3:a:xwiki:cryptpad:2025.6.0
-
cpe:2.3:a:xwiki:cryptpad:2025.9.0
-
cpe:2.3:a:xwiki:cryptpad:2026.2.0
-
cpe:2.3:a:xwiki:cryptpad:2026.2.1