Denial of Service Vulnerability in Telerik UI for AJAX by Progress
CVE-2026-14865

5.3MEDIUM

What is CVE-2026-14865?

The Telerik UI for AJAX product by Progress contains a vulnerability in its internal LayoutBuilder control, which processes client-state XML without disabling DTD processing. This flaw allows for unauthenticated denial of service, enabling attackers to exploit recursive XML entity expansion, potentially leading to resource exhaustion and service disruptions. It is crucial for users of affected versions to implement necessary updates to safeguard their applications from such threats.

Affected Version(s)

Telerik UI for ASP.NET AJAX 2009.1.314 < 2026.2.708

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Marcio Almeida of TantoSec
.