Skip to content
Progress SoftwareCVE-2026-13183

In Progress Telerik UI for AJAX prior to v2026.2.708

High7.5CVE-2026-13183 · Published Jul 22, 2026 · updated Aug 6, 2026

In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, enabling remote attackers to recover protected metadata values.

Progress Software advisory

Affected versions

PackageAffectedFixed in
Telerik UI for ASP.NET AJAX
Product
>= 2010.1.309, < 2026.2.7082026.2.708
Details and references

More Progress Software advisories

All Progress Software
Advisory
Progress Software Telerik UI for ASP.NET AJAX: denial of service
Medium5.3Jul 22
Progress Software Telerik UI for ASP.NET AJAX: hard-coded key
Medium6.5Jul 22
Progress Software Telerik UI for ASP.NET AJAX: remote code execution
High8.1Jul 22
Progress Software Telerik UI for ASP.NET AJAX: path traversal
High8.1Jul 22
In Progress Telerik UI for AJAX prior to v2026.2.708
High8.1Jul 22
Progress Software Telerik UI for ASP.NET AJAX: insufficient authenticity check
Medium5.9Jul 22

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.