CVE-2026-6022

In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vulnerability that allows file uploads to exceed the configured maximum size due to missing cumulative size enforcement during chunk reassembly, leading to disk space exhaustion.
Configurations

Configuration 1 (hide)

cpe:2.3:a:progress:telerik_ui_for_asp.net_ajax:*:*:*:*:*:*:*:*

History

05 May 2026, 18:39

Type Values Removed Values Added
First Time Progress
Progress telerik Ui For Asp.net Ajax
CPE cpe:2.3:a:progress:telerik_ui_for_asp.net_ajax:*:*:*:*:*:*:*:*
References () https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-uncontrolled-resource-consumption-cve-2026-6022 - () https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-uncontrolled-resource-consumption-cve-2026-6022 - Mitigation, Vendor Advisory

22 Apr 2026, 08:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-22 08:16

Updated : 2026-05-05 18:39


NVD link : CVE-2026-6022

Mitre link : CVE-2026-6022

CVE.ORG link : CVE-2026-6022


JSON object : View

Products Affected

progress

  • telerik_ui_for_asp.net_ajax
CWE
CWE-400

Uncontrolled Resource Consumption