In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vulnerability that allows file uploads to exceed the configured maximum size due to missing cumulative size enforcement during chunk reassembly, leading to disk space exhaustion.
References
| Link | Resource |
|---|---|
| https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-uncontrolled-resource-consumption-cve-2026-6022 | Mitigation Vendor Advisory |
Configurations
History
05 May 2026, 18:39
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Progress
Progress telerik Ui For Asp.net Ajax |
|
| CPE | cpe:2.3:a:progress:telerik_ui_for_asp.net_ajax:*:*:*:*:*:*:*:* | |
| References | () https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-uncontrolled-resource-consumption-cve-2026-6022 - Mitigation, Vendor Advisory |
22 Apr 2026, 08:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-22 08:16
Updated : 2026-05-05 18:39
NVD link : CVE-2026-6022
Mitre link : CVE-2026-6022
CVE.ORG link : CVE-2026-6022
JSON object : View
Products Affected
progress
- telerik_ui_for_asp.net_ajax
CWE
CWE-400
Uncontrolled Resource Consumption
