CVE-2026-6022 PUBLISHED

Uncontrolled Resource Consumption Vulnerability in Telerik UI for ASP.NET AJAX

Assigner: ProgressSoftware
Reserved: 09.04.2026 Published: 22.04.2026 Updated: 22.04.2026

In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vulnerability that allows file uploads to exceed the configured maximum size due to missing cumulative size enforcement during chunk reassembly, leading to disk space exhaustion.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
CVSS Score: 7.5

Product Status

Vendor Progress Software
Product Telerik UI for ASP.NET AJAX
Versions Default: unaffected
  • affected from 2011.2.712 to 2026.1.421 (excl.)

Credits

  • Monetary Authority of Singapore finder

References

Problem Types

  • CWE-400 Uncontrolled Resource Consumption CWE

Impacts

  • CAPEC-572 Artificially Inflate File Sizes