CryptPad's summer 2026 status and the post-quantum bottleneck

CryptPad, an end-to-end encrypted collaboration suite, has a new security policy that keeps vulnerability details private for at least 90 days after a fix ships. Its post-quantum experiment left some features too slow to use, and native browser support for the algorithms may change that. People on public instances need not change anything, while self-hosting administrators should keep up with releases.

CryptPad published its summer 2026 status on 15 September, covering a new security policy, post-quantum research and a support change on cryptpad.fr, its flagship instance. CryptPad is an AGPL-3.0 end-to-end encrypted suite for co-editing documents and spreadsheets in the browser. You can use a public instance or host your own. Users of public instances need not change anything, while self-hosting administrators should watch for upgrades.

According to the June post-mortem, the server did not rate-limit WebSocket connections, the channel through which the browser and server exchange data, so repeatedly sending frames could exhaust its resources. On 28 January cryptpad.fr was hit by a distributed denial-of-service attack exploiting that gap, and the resulting outage was resolved in under three hours. The fix shipped in 2026.2.1 on 27 March.

The team had intended a 90-day embargo, but the reporter disputed it because the previous policy did not state it clearly. The CVE was published 34 days after 2026.2.1. The new policy, published in June, keeps a CVE private for at least 90 days after the fixed release.

For post-quantum cryptography, the team chose NIST's ML-KEM, used to exchange keys, and ML-DSA, used for digital signatures. In experiments the two were combined with CryptPad's existing public-key cryptography in a hybrid way. Most of CryptPad ran smoothly, but some parts became too slow to use. According to the post, a draft adding both algorithms to the browser's Web Cryptography API should be two orders of magnitude faster than an external library.

The flagship instance, cryptpad.fr, will drop French-language support because the support team no longer has a French speaker. An Autumn Release bundling two releases' worth of improvements is coming, with no release date announced as of 29 September.

Perspective

CryptPad encrypts documents in the browser, and the server has no access to their content. The user guide lists several trust assumptions, including that the instance runs the same code as published on GitHub and that sharing links do not reach illegitimate third parties. When they all hold, administrators cannot read or modify your documents. The guide also states that CryptPad offers only weak anonymity, since the instance can see your IP address and browser, and points to Tor for stronger guarantees.

A fix takes effect only once an instance's administrators upgrade. Under the security policy, the 90-day embargo gives them time to do so before the vulnerability is published and attackers may start exploiting it. The public instance list only includes instances that pass checks for an up-to-date version, so it is a good place to start when choosing one.

The Web Cryptography API draft is maintained by the WICG, a W3C community group for new specifications, and as of 29 September it was not on the W3C standards track. Browser support may make a post-quantum CryptPad more realistic. The team has already restructured the code for crypto-agility, so cryptographic libraries can be swapped more easily.

As of 29 September, CryptPad's Weblate shows the interface fully translated into Traditional and Simplified Chinese, 96.6% into Japanese and only 5.8% into Korean. The user guide has a Japanese edition but no Chinese or Korean one. The support page shows which languages an instance's administrators use, and the guide suggests an online translator when needed.

In mainland China, GreatFire rates https://cryptpad.fr as not blocked as of 29 September, based on a single test on 18 September whose connection was refused. Since late August GreatFire no longer counts refusals as evidence of blocking. The hosts the editor also needs, such as api.cryptpad.fr and sandbox.cryptpad.info, had not been tested, so as of 29 September there was no reliable measurement. GitHub, where the source code and releases are published, showed interference in 69% of 54 conclusive tests over the 90 days to 27 September.

To try it, open cryptpad.fr or another listed instance in a browser with JavaScript enabled. All 13 instances on the public list are hosted in Europe or North America as of 29 September. Without an account you can still co-edit documents, but you cannot upload images, videos or PDFs, and a document unused for three months is no longer kept.

Registering needs only a username and password, with no email address. Because of the encryption, administrators cannot view, retrieve or reset a password, so the guide advises noting it somewhere safe.

According to the post-mortem, administrators running CryptPad behind nginx with a variation of the official advanced configuration should update it from the latest example configuration as soon as possible, since the new example adds rate limiting. Severity is now scored with CVSS 4.0, and release notes list only the highest score among fixed vulnerabilities plus a notice to upgrade. Each version is supported for 90 days. The recommended version is always the latest, with new versions published quarterly, and as of 29 September the latest release was 2026.5.1 from 26 May.

Get new stories by RSS, newsletter or Bluesky