What is CVE-2026-13183?
This vulnerability exists in the RadAsyncUpload component of Progress® Telerik® UI for AJAX, affecting versions prior to v2026.2.708. The flaw allows remote attackers to recover protected metadata values by exploiting measurable timing differences during the processing of upload metadata, which leaks cryptographic validity information. Immediate update to v2026.2.708 or later is required to mitigate the risk.
Azərbaycanca: Bu boşluq, Progress® Telerik® UI for AJAX platformasının RadAsyncUpload komponentində tapılıb. Zəiflik, fayl yükləmə metadatasının emalı zamanı yaranan ölçülə bilən zaman fərqləri (timing differences) səbəbindən kriptoqrafik təsdiqləmə məlumatlarının sızmasına, uzaqdan hücum edən şəxslərə qorunan metadata dəyərlərini bərpa etməyə imkan verir. Təsirə məruz qalmamaq üçün Telerik UI for AJAX məhsulunu dərhal v2026.2.708 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
Which product is affected by CVE-2026-13183?
This vulnerability exists in the RadAsyncUpload component of Progress® Telerik® UI for AJAX.
Which version should be updated to in order to mitigate CVE-2026-13183?
Immediate update to Telerik UI for AJAX v2026.2.708 or later is required to mitigate the risk.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.