Stats Digest Feeds
← Back to all CVEs

CVE-2026-14865

MEDIUM NVD
CVSS Score 5.3
Severity MEDIUM
Published Jul 22, 2026
Vendor unknown

Description

In Progress® Telerik® UI for AJAX prior to v2026.2.708, the internal LayoutBuilder control processes client-state XML without disabling DTD processing, allowing unauthenticated denial of service via recursive XML entity expansion.

References