Description
In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vulnerability that allows file uploads to exceed the configured maximum size due to missing cumulative size enforcement during chunk reassembly, leading to disk space exhaustion.
Problem types
CWE-400 Uncontrolled Resource Consumption
Product status
2011.2.712 (custom) before 2026.1.421
Credits
Monetary Authority of Singapore
References
www.telerik.com/...rolled-resource-consumption-cve-2026-6022