216.73.217.22

CVE-2025-51846

· Published 30/04/2026 17:16 · Modified 30/04/2026 17:20

Labels: CVE-2025-51846 2026-04-309119a7d8-5eab-497f-8521-727c672e3725CVE-2025-51846CWE-770

Essential information

Published
30/04/2026 17:16
Modified
30/04/2026 17:20
Author
Creator
CVSS
8.7 HIGH (v3) 8.7 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

CryptPad 2025.3.1 allows unbounded WebSocket frame flood. A remote, unauthenticated attacker can significantly degrade or deny service for all users of a CryptPad instance. Fixed in 2026.2.2.

NVD status

Status
Awaiting Analysis — CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.
Source
9119a7d8-5eab-497f-8521-727c672e3725
NVD
View on NVD

Affected products (CPE)

ProductCPE
cryptpad / cryptpad cpe:2.3:a:cryptpad:cryptpad:<2025.3.1:*:*:*:*:*:*:*

References