CVE-2026-77802: HTTP Request Smuggling Vulnerability in Progress® Telerik® Fiddler® Classic

Published Oct 5, 2026
·
Updated

In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, HTTP request smuggling is possible in the proxy request forwarding component. Requests containing multiple Content-Length headers with conflicting values are forwarded verbatim to the origin server, while Fiddler frames the request body using only the first Content-Length value. A local threat actor with low privileges who is able to send requests through the same Fiddler proxy instance as another user can exploit this desynchronization against a non-RFC-9110-compliant origin server that keeps the connection alive to smuggle an additional request. Because Fiddler returns the server connection to its pipe pool after reading only the first response, the unread smuggled response remains buffered on the socket and is served to the next session that reuses that connection, allowing the attacker to poison responses delivered to other users and to obtain responses intended for them.

Affected Software

1 affected component
Progress Telerik Fiddler Classic<6.0.20262.10021

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Progress Telerik Fiddler Classic for Windows to a version that resolves this vulnerability.

    Fixed in 6.0.20262.10021

Event History

Oct 5, 2026
CVE Published
via MITRE·12:38 PM
Data Sourced
via MITRE·12:38 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to exploitation in practice?

Exposure requires a local low-privileged attacker who can send traffic through the same Fiddler proxy instance as another user. The origin server must also be non-RFC-9110-compliant and keep the affected connection alive.

2

What request pattern is required to exploit the issue?

The attacker needs to submit a request with multiple conflicting Content-Length headers through the shared proxy. Fiddler uses the first value to frame the body but forwards all headers unchanged, enabling a desynchronization with the origin server.

3

How can this affect other proxy users?

After Fiddler reads the first server response, it returns the connection to its pool even if a smuggled response remains unread. A later session reusing that connection can receive the buffered response, allowing response poisoning and disclosure of responses intended for other users.

4

Which versions need remediation?

Fiddler Classic for Windows versions prior to v6.0.20262.10021 are affected. Upgrade to v6.0.20262.10021 or a later version.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203