PT-2026-63406 · Progress · Telerik Ui For Asp.Net Ajax

·

CVE-2026-14865

·

Published

2026-07-22

·

Updated

2026-07-22

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L
In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control processes client-state XML without disabling DTD processing, allowing unauthenticated denial of service via recursive XML entity expansion.

Fix

XML Entity Expansion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-14865

Affected Products

Telerik Ui For Asp.Net Ajax