CyberRota Analysis
AI-GeneratedThe internal LayoutBuilder control in Progress® Telerik® UI for AJAX versions prior to v2026.2.708 is vulnerable to denial of service due to improper handling of client-state XML, specifically allowing recursive XML entity expansion without DTD processing disabled. This could be exploited by unauthenticated attackers to disrupt service availability. Organizations using affected versions should prioritize remediation to mitigate potential service interruptions.
Original NVD Description
In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control processes client-state XML without disabling DTD processing, allowing unauthenticated denial of service via recursive XML entity expansion.
Related CVEs
Other vulnerabilities affecting the same vendor(s)