CVE-2026-13183

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/07/2026
Last modified:
06/08/2026

Description

In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, enabling remote attackers to recover protected metadata values.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:progress:telerik_ui_for_asp.net_ajax:*:*:*:*:*:*:*:* 2010.1309 (including) 2026.2.708 (excluding)