Progress Telerik UI for AJAX Uncontrolled Resource Consumption Vulnerability in RadAsyncUpload

Vulnerability

A vulnerability allowing uncontrolled resource consumption has been identified in Progress Telerik UI for AJAX versions prior to 2026.1.421. The issue resides in the RadAsyncUpload component, where file uploads can surpass the set maximum size limit. This occurs due to a lack of cumulative size enforcement during the reassembly of upload chunks, ultimately leading to disk space exhaustion.

Impact

Exploitation of this vulnerability can cause disk space exhaustion, potentially leading to a denial of service condition on the affected system.

Added: Apr 22, 2026, 8:24 AM
Updated: Apr 22, 2026, 8:24 AM

Vulnerability Rating

Custom Algorithm
spread
4.2
impact
2.5
exploitability
4.7
remediation
0.0
relevance
6.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.