Loading market data...
← Back to CVE feed

CVE-2026-6022

HIGH CVSS 7.5 View on NVD ↗

Description

In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vulnerability that allows file uploads to exceed the configured maximum size due to missing cumulative size enforcement during chunk reassembly, leading to disk space exhaustion.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Published: Apr 22, 2026 08:16 UTC Modified: Apr 22, 2026 21:23 UTC