In ProgressĀ® TelerikĀ® UI for AJAX, versions prior to 2026.1.225, an insufficient entropy vulnerability exists in RadAsyncUpload, where a predictable temporary identifier, based on timestamp and filename, can enable collisions and file content tampering.
The product uses an algorithm or scheme that produces insufficient entropy, leaving patterns or clusters of values that are more likely to occur than others.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Telerik_ui_for_asp.net_ajax | Progress | * | 2026.1.225 (excluding) |