Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2026-6022

Опубликовано: 22 апр. 2026
Источник: nvd
CVSS3: 7.5
EPSS Низкий

Описание

In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vulnerability that allows file uploads to exceed the configured maximum size due to missing cumulative size enforcement during chunk reassembly, leading to disk space exhaustion.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:progress:telerik_ui_for_asp.net_ajax:*:*:*:*:*:*:*:*
Версия до 2026.1.421 (исключая)

EPSS

Процентиль: 21%
0.00288
Низкий

7.5 High

CVSS3

Дефекты

CWE-400

Связанные уязвимости

CVSS3: 7.5
github
4 месяца назад

In Progress® Telerik® UI for AJAX prior to 2026.1.421, RadAsyncUpload contains an uncontrolled resource consumption vulnerability that allows file uploads to exceed the configured maximum size due to missing cumulative size enforcement during chunk reassembly, leading to disk space exhaustion.

EPSS

Процентиль: 21%
0.00288
Низкий

7.5 High

CVSS3

Дефекты

CWE-400