← All reports

The RadAsyncUpload component in Telerik UI for ASP.NET AJAX versions prior to 2026.1.421 is vulnerable to uncontrolled resource consumption, allowing file uploads to exceed the configured maximum size.

CybersecurityTechnologyConflictInformation SecurityApr 22, 2026score 0.172 posts · 0 replies across 1 instances
The thread discusses two cybersecurity vulnerabilities in Progress Software's Telerik UI for ASP.NET AJAX product. The first is an uncontrolled resource consumption vulnerability in RadAsyncUpload, and the second is an insecure deserialization vulnerability in RadFilter. Both vulnerabilities pose security risks and have been addressed in updated versions.

Claims

The RadAsyncUpload component in Telerik UI for ASP.NET AJAX versions prior to 2026.1.421 is vulnerable to uncontrolled resource consumption, allowing file uploads to exceed the configured maximum size.
Parent: CybersecurityEntity: Telerik UI for ASP.NET AJAXImpact: negativeDate: Apr 22, 2026Target: The security of Telerik UI for ASP.NET AJAX
The RadFilter control in Telerik UI for ASP.NET AJAX versions 2024.4.1114 through 2026.1.421 is vulnerable to insecure deserialization when restoring filter state, allowing attackers to tamper with the state.
Parent: CybersecurityEntity: Telerik UI for ASP.NET AJAXImpact: negativeDate: Apr 22, 2026Target: The security of Telerik UI for ASP.NET AJAX

Source posts

@[email protected]
🚨 EUVD-2026-24631 📊 Score: 7.5/10 (CVSS v3.1) 📦 Product: Telerik UI for ASP.NET AJAX 🏢 Vendor: Progress Software 📅 Updated: 2026-04-22 📝 In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vulnerability that allows file uploads to exceed the configured maximum size due to missing cumulative size enfo... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24631 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts · 0 favs · 0 replies · Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability
@[email protected]
🚨 EUVD-2026-24632 📊 Score: 8.1/10 (CVSS v3.1) 📦 Product: Telerik UI for ASP.NET AJAX 🏢 Vendor: Progress Software 📅 Updated: 2026-04-22 📝 In Progress® Telerik® UI for AJAX versions 2024.4.1114 through 2026.1.421, the RadFilter control is vulnerable to insecure deserialization when restoring filter state if the state is exposed to the client. If an attacker tampers... 🔗 https://euvd.enisa.europa.eu/vulnerability/EUVD-2026-24632 #cybersecurity #infosec #euvd #cve #vulnerability
0 boosts · 0 favs · 0 replies · Apr 22, 2026
#cybersecurity#infosec#euvd#cve#vulnerability