Summary
CVE-2026-13182 is a high-severity cryptographic (padding) oracle vulnerability in the RadAsyncUpload component of Progress Telerik UI for ASP.NET AJAX. The flaw affects all versions from 2010.1.309 through 2026.2.519, and allows unauthenticated remote attackers to progressively recover protected metadata values by exploiting the component’s differentiated error responses during client-state processing. The vulnerability carries a CVSS v3.1 base score of 7.5 (High).
Technical details
- Root cause: The RadAsyncUpload component’s client-state processing returns distinguishable responses depending on whether a submitted payload triggers a decryption failure or an invalid-JSON parse failure (CWE-209: Generation of Error Message Containing Sensitive Information). This behavioral difference constitutes a classic cryptographic oracle (CAPEC-463: Padding Oracle Crypto Attack).
- Trigger condition: An attacker submits crafted client-state payloads to the RadAsyncUpload HTTP handler endpoint (accessible via the
Telerik.Web.UI.WebResource.axdhandler withtype=rau). By iterating over malformed ciphertext blocks and observing differing server responses, the attacker can deduce plaintext content one block at a time — without needing to know the application’s encryption keys. - Attack vector: Network-reachable, no authentication required, no user interaction required, low attack complexity. The handler is exposed as a public HTTP endpoint on any application that uses RadAsyncUpload.
- Impact: High confidentiality impact — protected metadata values embedded in encrypted client state are recoverable. Historically, recovering such metadata from RadAsyncUpload has enabled chaining into .NET deserialization attacks leading to remote code execution, as documented by CISA in advisory AA23-074A in the context of CVE-2019-18935 and CVE-2017-11317.
Affected software
- Progress Telerik UI for ASP.NET AJAX versions 2010.1.309 through 2026.2.519 (all releases up to and including the 2026 Q2 base release)
Severity
CVSS v3.1 Base Score: 7.5 (High)
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Mitigation and recommended actions
- Immediate — apply the vendor patch: Upgrade to Telerik UI for ASP.NET AJAX version 2026.2.708 (2026 Q2 SP1) or later. Version 2026.2.708 introduces AES-GCM authenticated encryption for RadAsyncUpload client state, which is not vulnerable to padding oracle attacks.
- If immediate patching is not feasible — apply vendor-recommended workarounds:
- Remove custom
Telerik.AsyncUpload.ConfigurationEncryptionKeyandTelerik.Upload.ConfigurationHashKeyvalues fromweb.configso the component falls back toMachineKey.Unprotect(AES + HMAC), eliminating the oracle differential. - Generate and configure strong machine keys in IIS using HMACSHA256 validation to harden the fallback path.
- Set ASP.NET
customErrorsto"On"or"RemoteOnly"to suppress differentiated error responses visible to remote clients. - If RadAsyncUpload is not actively used by the application, disable the handler entirely by setting the application setting
Telerik.Web.DisableAsyncUploadHandlertotrueinweb.config.
- Remove custom
IONIX Status
The IONIX research team is tracking ongoing exploitation attempts and recommends immediate patching. Potentially affected assets are outlined in this post.

