Front-End Request Desynchronization in Telerik Fiddler Classic for Windows
CVE-2026-77803
Key Information:
- Vendor
Progress Software
- Vendor
- CVE Published:
- 5 October 2026
What is CVE-2026-77803?
Telerik Fiddler Classic for Windows is susceptible to a front-end request desynchronization vulnerability in its proxy request forwarding component. This occurs when a request containing both a Content-Length and a Transfer-Encoding header is processed. In such cases, Fiddler erroneously forwards both headers while framing the body exclusively using Transfer-Encoding, which can lead to improper parsing. This mismanagement allows a low-privilege local threat actor to split a malformed request into two separate requests sent to the origin server, enabling the attacker to receive an additional smuggled response. This security flaw necessitates immediate attention for users operating affected versions.
Affected Version(s)
Progress® Telerik® Fiddler® Classic Windows 1.0.0 < 6.0.20262.10021