In ProgressĀ® TelerikĀ® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vulnerability that allows file uploads to exceed the configured maximum size due to missing cumulative size enforcement during chunk reassembly, leading to disk space exhaustion.
References
| Link | Resource |
|---|---|
| https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-uncontrolled-resource-consumption-cve-2026-6022 | Mitigation Vendor Advisory |
Configurations
History
No history.
Information
Published : 2026-04-22 08:16
Updated : 2026-06-17 11:00
NVD link : CVE-2026-6022
Mitre link : CVE-2026-6022
CVE.ORG link : CVE-2026-6022
JSON object : View
Products Affected
progress
- telerik_ui_for_asp.net_ajax
CWE
CWE-400
Uncontrolled Resource Consumption
