Front-end Desynchronization Vulnerability (CVE-2026-77803)
Description
August 2026 - CVE-2026-77803
- Progress® Telerik® Fiddler® Classic 2026 (6.0.20261.7291) or earlier.
What Are the Impacts
In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, front-end request desynchronization is possible in the proxy request forwarding component.
Issue
- CWE-444: Inconsistent Interpretation of HTTP Requests.
- CAPEC-33: HTTP Request Smuggling.
Solution
We have addressed the issue and the Progress Telerik team strongly recommends performing an upgrade to the latest version listed in the table below.
| Current Version | Update to |
|---|---|
>= 1.0.0 && <= 6.0.20261.7291 (2026) | >= 6.0.20262.10021 (2026) |
Follow the update instructions for precise instructions or download the latest version of Progress® Telerik® Fiddler® Classic from this link.
Mitigation
If an immediate upgrade is not possible, apply the following measures to reduce risk:
- Disable client connection reuse in Fiddler Classic: open Tools > Options > Connections and uncheck the "Reuse client connections" checkbox. Disabling the client pipe reuse removes the possibility to execute such requests.
Notes
- If you have any questions or concerns related to this issue, open a new Technical Support case in Your Account | Support Center. Technical Support is available to customers with an active support plan.
- We would like to thank NATO Cyber Security Centre (NCSC) for responsibly disclosing this vulnerability.
External References
CVE-2026-77803 (LOW)
CVSS: 3.6
In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, front-end request desynchronization is possible in the proxy request forwarding component. A request that contains both a Content-Length and a Transfer-Encoding header is forwarded with both headers present, while Fiddler frames the body using Transfer-Encoding only. The remaining bytes on the reused client connection are then parsed as a separate pipelined request, so a local threat actor with low privileges can cause a single malformed request to be split into two requests forwarded to the origin server and receive an additional smuggled response, without requiring a vulnerable server.
Discoverer Credit: NATO Cyber Security Centre (NCSC)