CVE-2026-77803
Received Received - Intake

Front-end Request Deserialization in Telerik Fiddler Classic

Vulnerability report for CVE-2026-77803, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-05

Last updated on: 2026-10-05

Assigner: Progress Software Corporation

Description

In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, front-end request desynchronization is possible in the proxy request forwarding component. A request that contains both a Content-Length and a Transfer-Encoding header is forwarded with both headers present, while Fiddler frames the body using Transfer-Encoding only. The remaining bytes on the reused client connection are then parsed as a separate pipelined request, so a local threat actor with low privileges can cause a single malformed request to be split into two requests forwarded to the origin server and receive an additional smuggled response, without requiring a vulnerable server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-05
Last Modified
2026-10-05
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
Progress Software Progress® Telerik® Fiddler® Classic 1.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-444 The product acts as an intermediary HTTP agent (such as a proxy or firewall) in the data flow between two entities such as a client and server, but it does not interpret malformed HTTP requests or responses in ways that are consistent with how the messages will be processed by those entities that are at the ultimate destination.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a front-end request desynchronization issue in Progress Telerik Fiddler Classic for Windows, versions before v6.0.20262.10021. It occurs when a request contains both a Content-Length and a Transfer-Encoding header. Fiddler forwards the request with both headers intact but processes the body using only Transfer-Encoding. This causes the remaining bytes on the reused client connection to be misinterpreted as a separate pipelined request, allowing a local attacker with low privileges to split a single malformed request into two forwarded requests and receive an additional smuggled response.

Detection Guidance

To detect this vulnerability, monitor network traffic for malformed HTTP requests containing both Content-Length and Transfer-Encoding headers. Check if Fiddler Classic versions prior to v6.0.20262.10021 are installed and inspect proxy logs for desynchronization events.

Impact Analysis

A local attacker with low privileges could exploit this to send unauthorized requests to the origin server, potentially accessing sensitive data or performing actions on behalf of the user. The impact includes data leakage, unauthorized transactions, or manipulation of responses received by the client.

Compliance Impact

This vulnerability could lead to unauthorized access or data exposure, which may violate GDPR's data protection principles or HIPAA's requirements for safeguarding protected health information. Organizations using affected versions may face compliance risks, including potential fines or legal consequences.

Mitigation Strategies

Immediately update Fiddler Classic to version v6.0.20262.10021 or later. If updating is not possible, disable the proxy request forwarding feature or restrict low-privilege user access to the proxy.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-77803. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart