CVE-2026-77803: Front-end Desynchronization Vulnerability in Progress® Telerik® Fiddler® Classic
In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, front-end request desynchronization is possible in the proxy request forwarding component. A request that contains both a Content-Length and a Transfer-Encoding header is forwarded with both headers present, while Fiddler frames the body using Transfer-Encoding only. The remaining bytes on the reused client connection are then parsed as a separate pipelined request, so a local threat actor with low privileges can cause a single malformed request to be split into two requests forwarded to the origin server and receive an additional smuggled response, without requiring a vulnerable server.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Progress Telerik Fiddler Classic for Windowsto a version that resolves this vulnerability.Fixed in 6.0.20262.10021
Event History
Frequently Asked Questions
Who is exposed to exploitation?
The issue requires a local threat actor with low privileges. It affects Fiddler Classic for Windows when its proxy request forwarding component is used.
Does exploitation depend on a vulnerable origin server?
No. The described request splitting and additional smuggled response can occur without a vulnerable server.
What must an attacker send to trigger the issue?
The attacker needs to send a malformed request containing both Content-Length and Transfer-Encoding headers. Fiddler forwards both headers but frames the body using Transfer-Encoding, leaving remaining bytes to be parsed as a separate pipelined request on a reused client connection.
What should be updated?
Update to v6.0.20262.10021 or later. Versions before v6.0.20262.10021 are affected.