Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Mon, 04 May 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Xwiki
Xwiki cryptpad |
|
| CPEs | cpe:2.3:a:xwiki:cryptpad:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Xwiki
Xwiki cryptpad |
Fri, 01 May 2026 08:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Cryptpad
Cryptpad cryptpad |
|
| Vendors & Products |
Cryptpad
Cryptpad cryptpad |
Thu, 30 Apr 2026 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 30 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CryptPad 2025.3.1 allows unbounded WebSocket frame flood. A remote, unauthenticated attacker can significantly degrade or deny service for all users of a CryptPad instance. Fixed in 2026.2.2. | |
| Title | CryptPad unbounded WebSocket frame flood | |
| Weaknesses | CWE-770 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: cisa-cg
Published:
Updated: 2026-04-30T17:15:30.109Z
Reserved: 2025-06-16T03:28:36.966Z
Link: CVE-2025-51846
Updated: 2026-04-30T17:15:26.160Z
Status : Analyzed
Published: 2026-04-30T17:16:25.467
Modified: 2026-05-04T16:52:11.783
Link: CVE-2025-51846
No data.
OpenCVE Enrichment
Updated: 2026-05-01T08:21:13Z