CVE-2026-6022

EUVD-2026-24631
In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vulnerability that allows file uploads to exceed the configured maximum size due to missing cumulative size enforcement during chunk reassembly, leading to disk space exhaustion.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
ProgressSoftwareCNA
7.5 HIGH
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: Unknown
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
progresstelerik_ui_for_asp.net_ajax
2011.2.712 ≤
𝑥
< 2026.1.421
CNA