CVE-2026-13183: RadAsyncUpload Upload Metadata Timing Oracle Vulnerability in Telerik UI for ASP.NET AJAX
In Progress® Telerik® UI for AJAX prior to v2026.2.708, RadAsyncUpload upload metadata processing may leak cryptographic validity through measurable timing differences, enabling remote attackers to recover protected metadata values.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progress® Telerik® UI for AJAX (RadAsyncUpload)to a version that resolves this vulnerability.Fixed in 2026.2.708
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13183?
The severity of CVE-2026-13183 is rated as high with a CVSS score of 7.5.
How do I fix CVE-2026-13183?
To fix CVE-2026-13183, upgrade Telerik UI for ASP.NET AJAX to version 2026.2.708 or later.
What is the impact of CVE-2026-13183?
CVE-2026-13183 allows remote attackers to recover protected metadata values through timing differences in upload metadata processing.
Which version of Telerik UI for ASP.NET AJAX is affected by CVE-2026-13183?
CVE-2026-13183 affects all versions of Telerik UI for AJAX prior to v2026.2.708.
Is CVE-2026-13183 an information disclosure vulnerability?
Yes, CVE-2026-13183 is an information disclosure vulnerability that enables leakage of cryptographic metadata.