Description
In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, HTTP request smuggling is possible in the proxy request forwarding component. Requests containing multiple Content-Length headers with conflicting values are forwarded verbatim to the origin server, while Fiddler frames the request body using only the first Content-Length value. A local threat actor with low privileges who is able to send requests through the same Fiddler proxy instance as another user can exploit this desynchronization against a non-RFC-9110-compliant origin server that keeps the connection alive to smuggle an additional request. Because Fiddler returns the server connection to its pipe pool after reading only the first response, the unread smuggled response remains buffered on the socket and is served to the next session that reuses that connection, allowing the attacker to poison responses delivered to other users and to obtain responses intended for them.
Published: 2026-10-05
Score: 6.3 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

Vendor Workaround

Disable server connection reuse in Fiddler Classic: open Tools > Options > Connections and uncheck the "Reuse server connections" checkbox. Disabling server pipe reuse prevents a poisoned server connection from being handed to another session.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 05 Oct 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Progress
Progress telerik Fiddler Classic
Vendors & Products Progress
Progress telerik Fiddler Classic

Mon, 05 Oct 2026 13:00:00 +0000

Type Values Removed Values Added
Description In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, HTTP request smuggling is possible in the proxy request forwarding component. Requests containing multiple Content-Length headers with conflicting values are forwarded verbatim to the origin server, while Fiddler frames the request body using only the first Content-Length value. A local threat actor with low privileges who is able to send requests through the same Fiddler proxy instance as another user can exploit this desynchronization against a non-RFC-9110-compliant origin server that keeps the connection alive to smuggle an additional request. Because Fiddler returns the server connection to its pipe pool after reading only the first response, the unread smuggled response remains buffered on the socket and is served to the next session that reuses that connection, allowing the attacker to poison responses delivered to other users and to obtain responses intended for them.
Title HTTP Request Smuggling Vulnerability in Progress® Telerik® Fiddler® Classic
Weaknesses CWE-444
References
Metrics cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

Progress Telerik Fiddler Classic
cve-icon MITRE

Status: PUBLISHED

Assigner: ProgressSoftware

Published:

Updated: 2026-10-05T12:38:58.912Z

Reserved: 2026-08-21T13:37:28.618Z

Link: CVE-2026-77802

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-05T13:16:54.293

Modified: 2026-10-05T13:16:54.293

Link: CVE-2026-77802

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-05T15:15:08Z

Weaknesses
  • CWE-444

    Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling')