Front-end Desynchronization Vulnerability (CVE-2026-77803)

Updated on Oct 5, 2026

Description

August 2026 - CVE-2026-77803

  • Progress® Telerik® Fiddler® Classic 2026 (6.0.20261.7291) or earlier.

What Are the Impacts

In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, front-end request desynchronization is possible in the proxy request forwarding component.

Issue

  • CWE-444: Inconsistent Interpretation of HTTP Requests.
  • CAPEC-33: HTTP Request Smuggling.

Solution

We have addressed the issue and the Progress Telerik team strongly recommends performing an upgrade to the latest version listed in the table below.

Current VersionUpdate to
>= 1.0.0 && <= 6.0.20261.7291 (2026)>= 6.0.20262.10021 (2026)

Follow the update instructions for precise instructions or download the latest version of Progress® Telerik® Fiddler® Classic from this link.

Mitigation

If an immediate upgrade is not possible, apply the following measures to reduce risk:

  • Disable client connection reuse in Fiddler Classic: open Tools > Options > Connections and uncheck the "Reuse client connections" checkbox. Disabling the client pipe reuse removes the possibility to execute such requests.

Notes

  • If you have any questions or concerns related to this issue, open a new Technical Support case in Your Account | Support Center. Technical Support is available to customers with an active support plan.
  • We would like to thank NATO Cyber Security Centre (NCSC) for responsibly disclosing this vulnerability.

External References

CVE-2026-77803 (LOW)

CVSS: 3.6

In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, front-end request desynchronization is possible in the proxy request forwarding component. A request that contains both a Content-Length and a Transfer-Encoding header is forwarded with both headers present, while Fiddler frames the body using Transfer-Encoding only. The remaining bytes on the reused client connection are then parsed as a separate pipelined request, so a local threat actor with low privileges can cause a single malformed request to be split into two requests forwarded to the origin server and receive an additional smuggled response, without requiring a vulnerable server.

Discoverer Credit: NATO Cyber Security Centre (NCSC)