In Progress® Telerik® UI for AJAX, versions prior to 2026...
Moderate severity
Unreviewed
Published
Feb 25, 2026
to the GitHub Advisory Database
•
Updated Feb 25, 2026
Description
Published by the National Vulnerability Database
Feb 25, 2026
Published to the GitHub Advisory Database
Feb 25, 2026
Last updated
Feb 25, 2026
In Progress® Telerik® UI for AJAX, versions prior to 2026.1.225, an insufficient entropy vulnerability exists in RadAsyncUpload, where a predictable temporary identifier, based on timestamp and filename, can enable collisions and file content tampering.
References