Progress Telerik UI for AJAX
cpe:2.3:a:telerik:ui_for_asp.net_ajax:*:*:*:*:*:*:*
- < 2026.1.421
A vulnerability allowing uncontrolled resource consumption has been identified in Progress Telerik UI for AJAX versions prior to 2026.1.421. The issue resides in the RadAsyncUpload component, where file uploads can surpass the set maximum size limit. This occurs due to a lack of cumulative size enforcement during the reassembly of upload chunks, ultimately leading to disk space exhaustion.
Exploitation of this vulnerability can cause disk space exhaustion, potentially leading to a denial of service condition on the affected system.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.