Sceawere

Vulnerability Detail

CVE-2026-77803UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Telerik Fiddler Request Desynchronization Vulnerability

Vulnerability Metadata

Severity
Low
Score / CVSS
3.6
Creation Date
6h ago
Vendor
Progress Software
Product
Progress® Telerik® Fiddler® Classic
Attack Type
CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')
Vector String
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N
Attack Complexity
HIGH

Narrative and Response

Description

In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, front-end request desynchronization is possible in the proxy request forwarding component. A request that contains both a Content-Length and a Transfer-Encoding header is forwarded with both headers present, while Fiddler frames the body using Transfer-Encoding only. The remaining bytes on the reused client connection are then parsed as a separate pipelined request, so a local threat actor with low privileges can cause a single malformed request to be split into two requests forwarded to the origin server and receive an additional smuggled response, without requiring a vulnerable server.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "3.6",
  "pubDate": "2026-10-05T13:16:54.453Z",
  "pubdate": "2026-10-05T13:16:54.453Z",
  "executiveSummary": "A request desynchronization vulnerability exists in the proxy request forwarding component of Progress Telerik Fiddler Classic for Windows, specifically in versions prior to v6.0.20262.10021.\nThe vulnerability occurs due to improper handling of dual header definitions—specifically Content-Length and Transfer-Encoding—within forwarded HTTP requests.\nThis flaw allows a local, low-privileged threat actor to perform request smuggling, where a single malformed request is bifurcated by the proxy.\nBy causing the proxy to forward a payload that is interpreted differently by the proxy and the origin server, an attacker can effectively desynchronize the connection.\nThis leads to the injection of unauthorized requests into the server stream, potentially resulting in unauthorized data access, security control bypasses, or response manipulation.\nThe exploit does not require the origin server to be inherently vulnerable, as the desynchronization is induced by the proxy's own forwarding logic.\nThis represents a significant risk to the integrity of proxied traffic and downstream service security.",
  "technicalDetails": "The core of the vulnerability resides in the proxy request forwarding logic of Telerik Fiddler Classic, which fails to sanitize or consolidate conflicting HTTP request framing headers.\nWhen a request is submitted containing both 'Content-Length' and 'Transfer-Encoding' headers, the Fiddler proxy engine inconsistently applies framing logic. Fiddler frames the request body using 'Transfer-Encoding', yet it forwards both headers to the origin server.\nThis behavior creates a mismatch in how the proxy and the origin server define the boundaries of the request body. Because the proxy reuses the client connection, the bytes that the proxy intended to be part of a single request are misinterpreted by the origin server.\nThe 'leftover' bytes on the persistent client connection are subsequently parsed by the origin server as the start of a new, pipelined request. This effectively results in the smuggling of an arbitrary second request.\nAttack Flow: 1. The attacker crafts a malicious HTTP request featuring both Content-Length and Transfer-Encoding headers. 2. The Fiddler proxy receives this request and, due to the flaw, forwards the complete malformed header set to the destination. 3. The proxy frames the body based on the Transfer-Encoding header, while the origin server—relying on the forwarded headers—terminates the request prematurely based on the Content-Length or the end of the transfer-encoded stream. 4. Any data remaining in the buffer is interpreted by the server as a subsequent request. 5. The server processes this smuggled request, and the resulting response is returned to the attacker through the existing, reused connection.\nThe exploit requires the ability to reach the proxy interface. Given that Fiddler is a local interception proxy, a local low-privileged threat actor can leverage this to manipulate traffic intercepted from other processes or services on the same host.\nThe impact is significant, as it enables the execution of arbitrary commands or requests in the context of the origin server, bypassing expected application-level security checks or authentication boundaries if the server assumes the smuggled request is legitimate and subsequent to the initial authorized request.\nThis vulnerability persists in all versions of Fiddler Classic prior to v6.0.20262.10021, and successful exploitation demonstrates a failure in secure HTTP protocol normalization within the proxy's forwarding pipeline."
}
CVE-2026-77803: Telerik Fiddler Request Desynchronization Vulnerability (LOW Severity, CVSS: 3.6) | Sceawere