CVE-2026-77803: Front-end Desynchronization Vulnerability in Progress® Telerik® Fiddler® Classic

Published Oct 5, 2026
·
Updated

In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, front-end request desynchronization is possible in the proxy request forwarding component. A request that contains both a Content-Length and a Transfer-Encoding header is forwarded with both headers present, while Fiddler frames the body using Transfer-Encoding only. The remaining bytes on the reused client connection are then parsed as a separate pipelined request, so a local threat actor with low privileges can cause a single malformed request to be split into two requests forwarded to the origin server and receive an additional smuggled response, without requiring a vulnerable server.

Affected Software

1 affected component
Progress Telerik Fiddler Classic<6.0.20262.10021

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Progress Telerik Fiddler Classic for Windows to a version that resolves this vulnerability.

    Fixed in 6.0.20262.10021

Event History

Oct 5, 2026
CVE Published
via MITRE·12:39 PM
Data Sourced
via MITRE·12:39 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to exploitation?

The issue requires a local threat actor with low privileges. It affects Fiddler Classic for Windows when its proxy request forwarding component is used.

2

Does exploitation depend on a vulnerable origin server?

No. The described request splitting and additional smuggled response can occur without a vulnerable server.

3

What must an attacker send to trigger the issue?

The attacker needs to send a malformed request containing both Content-Length and Transfer-Encoding headers. Fiddler forwards both headers but frames the body using Transfer-Encoding, leaving remaining bytes to be parsed as a separate pipelined request on a reused client connection.

4

What should be updated?

Update to v6.0.20262.10021 or later. Versions before v6.0.20262.10021 are affected.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203