Impact
In Telerik UI for ASP.NET AJAX up to version 2026.2.708, the RadAsyncUpload component handles upload metadata in a way that leaks the cryptographic validity of protected values through measurable timing differences. A remote attacker who can observe the time required to process upload requests can infer sensitive metadata, potentially revealing secrets tied to the upload process. The weakness is recognized as a timing side‑channel defect, classified under CWE‑208.
Affected Systems
Progress Software’s Telerik UI for ASP.NET AJAX is impacted. All deployments utilizing versions earlier than 2026.2.708 are vulnerable; no additional vendors or products are listed as affected.
Risk and Exploitability
The CVSS score of 7.5 denotes a high‑severity information‑disclosure risk. The EPSS score of <1% indicates a very low but non‑zero chance of exploitation, and the vulnerability is not present in the CISA KEV catalog. Exploitation requires an attacker to send crafted upload requests to the RadAsyncUpload endpoint and achieve precise timing measurements; this can be performed remotely across the network. When an environment exposes the upload feature to untrusted users (inferred), the risk rises because the attacker can repeat tests to confirm and refine the inferred values.
OpenCVE Enrichment