CVE-2026-77802: HTTP Request Smuggling Vulnerability in Progress® Telerik® Fiddler® Classic
In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, HTTP request smuggling is possible in the proxy request forwarding component. Requests containing multiple Content-Length headers with conflicting values are forwarded verbatim to the origin server, while Fiddler frames the request body using only the first Content-Length value. A local threat actor with low privileges who is able to send requests through the same Fiddler proxy instance as another user can exploit this desynchronization against a non-RFC-9110-compliant origin server that keeps the connection alive to smuggle an additional request. Because Fiddler returns the server connection to its pipe pool after reading only the first response, the unread smuggled response remains buffered on the socket and is served to the next session that reuses that connection, allowing the attacker to poison responses delivered to other users and to obtain responses intended for them.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progress Telerik Fiddler Classic for Windowsto a version that resolves this vulnerability.Fixed in 6.0.20262.10021
Event History
Frequently Asked Questions
Who is exposed to exploitation in practice?
Exposure requires a local low-privileged attacker who can send traffic through the same Fiddler proxy instance as another user. The origin server must also be non-RFC-9110-compliant and keep the affected connection alive.
What request pattern is required to exploit the issue?
The attacker needs to submit a request with multiple conflicting Content-Length headers through the shared proxy. Fiddler uses the first value to frame the body but forwards all headers unchanged, enabling a desynchronization with the origin server.
How can this affect other proxy users?
After Fiddler reads the first server response, it returns the connection to its pool even if a smuggled response remains unread. A later session reusing that connection can receive the buffered response, allowing response poisoning and disclosure of responses intended for other users.
Which versions need remediation?
Fiddler Classic for Windows versions prior to v6.0.20262.10021 are affected. Upgrade to v6.0.20262.10021 or a later version.