Front-End Request Desynchronization in Telerik Fiddler Classic for Windows
CVE-2026-77803

3.6LOW

What is CVE-2026-77803?

Telerik Fiddler Classic for Windows is susceptible to a front-end request desynchronization vulnerability in its proxy request forwarding component. This occurs when a request containing both a Content-Length and a Transfer-Encoding header is processed. In such cases, Fiddler erroneously forwards both headers while framing the body exclusively using Transfer-Encoding, which can lead to improper parsing. This mismanagement allows a low-privilege local threat actor to split a malformed request into two separate requests sent to the origin server, enabling the attacker to receive an additional smuggled response. This security flaw necessitates immediate attention for users operating affected versions.

Affected Version(s)

Progress® Telerik® Fiddler® Classic Windows 1.0.0 < 6.0.20262.10021

References

CVSS V3.1

Score:
3.6
Severity:
LOW
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

NATO Cyber Security Centre (NCSC)
.