HTTP Request Smuggling Vulnerability in Telerik Fiddler Classic for Windows
CVE-2026-77802

6.3MEDIUM

What is CVE-2026-77802?

The Telerik Fiddler Classic for Windows contains a vulnerability in its proxy request forwarding component that allows HTTP request smuggling. Attackers can exploit this by sending requests that contain multiple, conflicting Content-Length headers. This desynchronization can be leveraged against non-compliant origin servers, enabling attackers to smuggle malicious requests. The initial Content-Length value is used to frame the request body; however, if a local threat actor operates under the same proxy instance, they could manipulate the connection, leading to a scenario where smuggled responses are buffered. As a result, these unread responses may be erroneously delivered to unintended users, compromising response integrity and potentially disclosing sensitive information.

Affected Version(s)

Progress® Telerik® Fiddler® Classic Windows 1.0.0 < 6.0.20262.10021

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

NATO Cyber Security Centre (NCSC)
.