CVE-2026-77803 PUBLISHED

Front-end Desynchronization Vulnerability in Progress® Telerik® Fiddler® Classic

Assigner: ProgressSoftware
Reserved: 21.08.2026 Published: 05.10.2026 Updated: 05.10.2026

In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, front-end request desynchronization is possible in the proxy request forwarding component. A request that contains both a Content-Length and a Transfer-Encoding header is forwarded with both headers present, while Fiddler frames the body using Transfer-Encoding only. The remaining bytes on the reused client connection are then parsed as a separate pipelined request, so a local threat actor with low privileges can cause a single malformed request to be split into two requests forwarded to the origin server and receive an additional smuggled response, without requiring a vulnerable server.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
CVSS Score: 3.6

Product Status

Vendor Progress Software
Product Progress® Telerik® Fiddler® Classic
Versions Default: unaffected
  • affected from 1.0.0 to 6.0.20262.10021 (excl.)

Workarounds

Disable client connection reuse in Fiddler Classic: open Tools > Options > Connections and uncheck the "Reuse client connections" checkbox. Disabling client pipe reuse prevents the excess data of a malformed request from being parsed as a pipelined request.

Credits

  • NATO Cyber Security Centre (NCSC) finder

References

Problem Types

  • CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') CWE

Impacts

  • CAPEC-33 HTTP Request Smuggling