HTTP Request Smuggling Vulnerability (CVE-2026-77802)

Updated on Oct 5, 2026

Description

August 2026 - CVE-2026-77802

  • Progress® Telerik® Fiddler® Classic 2026 (6.0.20261.7291) or earlier.

What Are the Impacts

In Progress® Telerik® Fiddler® Classic for Windows, versions prior to 6.0.20262.10021, HTTP request smuggling is possible in the proxy request forwarding component.

Issue

  • CWE-444: Inconsistent Interpretation of HTTP Requests.
  • CAPEC-33: HTTP Request Smuggling.

Solution

We have addressed the issue and the Progress Telerik team strongly recommends performing an upgrade to the latest version listed in the table below.

Current VersionUpdate to
>= 1.0.0 && <= 6.0.20261.7291 (2026)>= 6.0.20262.10021 (2026)

Follow the update instructions for precise instructions or download the latest version of Progress® Telerik® Fiddler® Classic from this link.

Mitigation

If an immediate upgrade is not possible, apply the following measures to reduce risk:

  • Disable server connection reuse in Fiddler Classic: open Tools > Options > Connections and uncheck the "Reuse server connections" checkbox. Disabling the server pipe reuse removes the possibility to execute such attacks.

Notes

  • If you have any questions or concerns related to this issue, open a new Technical Support case in Your Account | Support Center. Technical Support is available to customers with an active support plan.
  • We would like to thank NATO Cyber Security Centre (NCSC) for responsibly disclosing this vulnerability.

External References

CVE-2026-77802 (MEDIUM)

CVSS: 6.3

In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, HTTP request smuggling is possible in the proxy request forwarding component. Requests containing multiple Content-Length headers with conflicting values are forwarded verbatim to the origin server, while Fiddler frames the request body using only the first Content-Length value. A local threat actor with low privileges who is able to send requests through the same Fiddler proxy instance as another user can exploit this desynchronization against a non-RFC-9110-compliant origin server that keeps the connection alive to smuggle an additional request. Because Fiddler returns the server connection to its pipe pool after reading only the first response, the unread smuggled response remains buffered on the socket and is served to the next session that reuses that connection, allowing the attacker to poison responses delivered to other users and to obtain responses intended for them.

Discoverer Credit: NATO Cyber Security Centre (NCSC)