- **Root Cause**: Missing cumulative size check in upload process.
- Related to **CWE-400**: Uncontrolled Resource Consumption.
- Flaw: No enforced limit while merging chunks 🧩.
Q3影响谁?(版本/组件)
- **Affected**: Progress Telerik UI for AJAX < **2026.1.421**.
- Component: **RadAsyncUpload**.
- 🎯 Web apps using vulnerable version.
Q4黑客能干啥?(权限/数据)
- **Hackers**: No need for auth 🛑.
- Can force large uploads → fill disk.
- 📉 Impact: **Availability** only (C:N / I:N / A:H).
- No direct data access or privilege gain.
- **If No Patch**:
- Enforce strict file size limits at server side 🚨.
- Disable or replace **RadAsyncUpload** if unused.
- Add custom checks during chunk reassembly 💡.…