CVE-2025-3600

In Progress® Telerik® UI for AJAX, versions 2011.2.712 to 2025.1.218, an unsafe reflection vulnerability exists that may lead to an unhandled exception resulting in a crash of the hosting process and denial of service.
Configurations

Configuration 1 (hide)

cpe:2.3:a:progress:telerik_ui_for_asp.net_ajax:*:*:*:*:*:*:*:*

History

27 Aug 2025, 15:15

Type Values Removed Values Added
CWE CWE-470

26 Aug 2025, 19:15

Type Values Removed Values Added
References () https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-unsafe-reflection-cve-2025-3600 - Vendor Advisory, Mitigation () https://www.telerik.com/products/aspnet-ajax/documentation/knowledge-base/kb-security-unsafe-reflection-cve-2025-3600 - Mitigation, Vendor Advisory
CWE CWE-400

25 Jun 2025, 15:29

Type Values Removed Values Added
New CVE

Information

Published : 2025-05-14 14:15

Updated : 2025-08-27 15:15


NVD link : CVE-2025-3600

Mitre link : CVE-2025-3600

CVE.ORG link : CVE-2025-3600


JSON object : View

Products Affected

progress

  • telerik_ui_for_asp.net_ajax
CWE
CWE-470

Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection')