Completed
Last Updated: 10 Sep 2026 07:58 by ADMIN
Release 2026 Q3
Owen
Created on: 09 Jul 2026 09:04
Category: AsyncUpload
Type: Bug Report
0
Disabling session state and csrf causes null reference exception when using async upload

If both the CSRF validation and the Session state is turned off, the pages containing AsyncUpload control will throw a null reference exception.

<appSettings>
  <add key="Telerik.AsyncUpload.EnableCsrfValidation" value="false" />
</appSettings>
<system.web>
  <sessionState mode="Off" />

3 comments
ADMIN
Attila Antal
Posted on: 10 Sep 2026 07:58

Hi Jean-Pierre,

Thank you for reporting the issue.

Based on the details you shared, I have:

  • disabled the Session state
  • disabled the CSRF validation (must be done if SessionState is off)
  • created a page with the provided markup code

Then I tried uploading a TXT and a CSV file, both of which were successful.

If the issue was related to to disabled Session state, the expected Status code would be 500 Internal Server Error and Exception Details: System.InvalidOperationException: Session state is not available.

Also, when I click on the Request's Preview tab, the StackTrace shows the code path and where this fails. Of course, this will only work if you do not have custom errors enabled.

The fact that you're getting 403 Forbidden, that tells me that a unknown Type is being used (e.g. Custom Handler, Custom Upload Configuration, Custom FileInfo, etc..) and the AsyncUpload control does not trust it. Please verify that if you're implementing custom handlers or any other custom types, these are defined in the Telerik.Upload.AllowedCustomMetaDataTypes key in web.config:

Example

<add key="Telerik.Upload.AllowedCustomMetaDataTypes" value="MyNamespace.MyCustomHandler;MyNamespace.MyCustomUploadConfiguration" />

If the issue still persists, please submit a support ticket and share all the details that will help us replicate the issue and we will troubleshoot it together.

Regards,
Attila Antal
Progress Telerik

Stay tuned by visiting our public roadmap and feedback portal pages! Or perhaps, if you are new to our Telerik family, check out our getting started resources! 
JP
Posted on: 02 Sep 2026 15:56

We just updated to Q3 2026 to see if this had been addressed. While null reference exception is not thrown, the upload itself seems to be failing when session state is disabled. When session state is enabled, it works fine though. Please check below screenshot that shows uploading failure and the network response.

 

Here is the markup, is there anything else that we need to configure?

 

ADMIN
Attila Antal
Posted on: 10 Jul 2026 08:04

Hi Owen,

Thank you for taking the time to report the regression and for providing such clear details. Your feedback helped us pinpoint the issue quickly.

I’m glad to confirm that the problems you identified have now been fixed. These improvements will be included in our upcoming 2026 Q3 release.

We appreciate your diligence and support.

Regards,
Attila Antal
Progress Telerik

Stay tuned by visiting our public roadmap and feedback portal pages! Or perhaps, if you are new to our Telerik family, check out our getting started resources!