Description
In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, enabling remote attackers to recover protected metadata values.
Published: 2026-07-22
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

In Telerik UI for ASP.NET AJAX up to version 2026.2.708, the RadAsyncUpload component handles upload metadata in a way that leaks the cryptographic validity of protected values through measurable timing differences. A remote attacker who can observe the time required to process upload requests can infer sensitive metadata, potentially revealing secrets tied to the upload process. The weakness is recognized as a timing side‑channel defect, classified under CWE‑208.

Affected Systems

Progress Software’s Telerik UI for ASP.NET AJAX is impacted. All deployments utilizing versions earlier than 2026.2.708 are vulnerable; no additional vendors or products are listed as affected.

Risk and Exploitability

The CVSS score of 7.5 denotes a high‑severity information‑disclosure risk. The EPSS score of <1% indicates a very low but non‑zero chance of exploitation, and the vulnerability is not present in the CISA KEV catalog. Exploitation requires an attacker to send crafted upload requests to the RadAsyncUpload endpoint and achieve precise timing measurements; this can be performed remotely across the network. When an environment exposes the upload feature to untrusted users (inferred), the risk rises because the attacker can repeat tests to confirm and refine the inferred values.

Generated by OpenCVE AI on August 4, 2026 at 15:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to Telerik UI for ASP.NET AJAX version 2026.2.708 or later, which removes the timing‑based metadata leakage.
  • Restrict network access to the RadAsyncUpload endpoint, allowing only trusted clients to submit upload requests.
  • Monitor upload traffic for abnormal timing patterns and audit logs for evidence of timing sniffing attempts.

Generated by OpenCVE AI on August 4, 2026 at 15:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 28 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Progress
Progress telerik Ui For Asp.net Ajax
Vendors & Products Progress
Progress telerik Ui For Asp.net Ajax

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Description In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, enabling remote attackers to recover protected metadata values.
Title RadAsyncUpload Upload Metadata Timing Oracle Vulnerability in Telerik UI for ASP.NET AJAX
Weaknesses CWE-208
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Progress Telerik Ui For Asp.net Ajax
cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-07-22T19:15:06.321Z

Reserved: 2026-06-24T13:46:38.096Z

Link: CVE-2026-13183

cve-icon Vulnrichment

Updated: 2026-07-22T19:15:01.579Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-22T14:17:13.807

Modified: 2026-08-06T18:10:19.943

Link: CVE-2026-13183

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T15:45:03Z

Weaknesses
  • CWE-208

    Observable Timing Discrepancy