Executive brief
A vulnerability exists in a popular web development toolkit used for building ASP.NET applications. Specifically, the component responsible for handling file uploads contains a flaw that allows an attacker to observe small timing differences when the system processes encrypted data. This could allow an unauthorized person to eventually recover sensitive internal configuration data, potentially leading to further compromise of the application's security.
Technical details
A timing oracle vulnerability (CWE-208) exists in the RadAsyncUpload handler of Telerik UI for ASP.NET AJAX. The vulnerability is rooted in the way upload metadata is cryptographically processed; measurable timing differences during validation allow an attacker to determine the validity of encrypted blobs. By sending crafted requests and measuring response times, a remote, unauthenticated attacker can perform a side-channel attack to recover protected metadata values. The issue affects versions from 2010.1.309 through 2026.2.519. It is resolved in version 2026.2.708 (2026 Q2 SP1) by implementing AES-GCM for metadata protection.
Affected products
- Progress Software Telerik UI for ASP.NET AJAX >= 2010.1.309, <= 2026.2.519
Timeline
- 2026-07-22: disclosed
- 2026-07-22: advisory
- 2026-07-22: patched