HTTP Request Smuggling Vulnerability in Telerik Fiddler Classic for Windows
CVE-2026-77802
Key Information:
- Vendor
Progress Software
- Vendor
- CVE Published:
- 5 October 2026
What is CVE-2026-77802?
The Telerik Fiddler Classic for Windows contains a vulnerability in its proxy request forwarding component that allows HTTP request smuggling. Attackers can exploit this by sending requests that contain multiple, conflicting Content-Length headers. This desynchronization can be leveraged against non-compliant origin servers, enabling attackers to smuggle malicious requests. The initial Content-Length value is used to frame the request body; however, if a local threat actor operates under the same proxy instance, they could manipulate the connection, leading to a scenario where smuggled responses are buffered. As a result, these unread responses may be erroneously delivered to unintended users, compromising response integrity and potentially disclosing sensitive information.
Affected Version(s)
Progress® Telerik® Fiddler® Classic Windows 1.0.0 < 6.0.20262.10021