Project Subscriptions
No data.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
Disable client connection reuse in Fiddler Classic: open Tools > Options > Connections and uncheck the "Reuse client connections" checkbox. Disabling client pipe reuse prevents the excess data of a malformed request from being parsed as a pipelined request.
Mon, 05 Oct 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, front-end request desynchronization is possible in the proxy request forwarding component. A request that contains both a Content-Length and a Transfer-Encoding header is forwarded with both headers present, while Fiddler frames the body using Transfer-Encoding only. The remaining bytes on the reused client connection are then parsed as a separate pipelined request, so a local threat actor with low privileges can cause a single malformed request to be split into two requests forwarded to the origin server and receive an additional smuggled response, without requiring a vulnerable server. | |
| Title | Front-end Desynchronization Vulnerability in Progress® Telerik® Fiddler® Classic | |
| Weaknesses | CWE-444 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: ProgressSoftware
Published:
Updated: 2026-10-05T12:39:36.806Z
Reserved: 2026-08-21T13:37:32.974Z
Link: CVE-2026-77803
No data.
Status : Received
Published: 2026-10-05T13:16:54.453
Modified: 2026-10-05T13:16:54.453
Link: CVE-2026-77803
No data.
OpenCVE Enrichment
Updated: 2026-10-05T15:15:08Z