CyberRota Analysis
AI-GeneratedThe vulnerability affects the Telerik UI for AJAX, specifically in the RadAsyncUpload component, where improper handling of client-state processing can allow remote attackers to differentiate between decryption failures and invalid JSON parse failures. This creates an oracle that can expose sensitive metadata values, potentially leading to unauthorized access to protected information. Organizations using affected versions should prioritize remediation to mitigate the risk of data exposure and maintain the integrity of their applications.
Original NVD Description
In ProgressĀ® TelerikĀ® UI for AJAX prior to v2026.2.708, RadAsyncUpload client-state processing can distinguish decrypt failures from invalid-JSON parse failures, creating an oracle that reveals protected metadata values to remote attackers.
Related CVEs
Other vulnerabilities affecting the same vendor(s)