脆弱性の種類
In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control processes client-state XML without disabling DTD processing, allowing unauthenticated denial of service via recursive XML entity expansion.
影響を受ける製品
- progress telerik_ui_for_asp.net_ajax