CVE-2026-77803: CWE-444: Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') in Progress Software Progress® Telerik® Fiddler® Classic
Description
CVE-2026-77803 is a low-severity HTTP request/response smuggling vulnerability in Progress Telerik Fiddler Classic for Windows versions prior to 6.0.20262.10021. The issue arises because the proxy forwards requests containing both Content-Length and Transfer-Encoding headers with both headers present, but frames the body using Transfer-Encoding only. This causes the remaining bytes on a reused client connection to be interpreted as a separate pipelined request. A local low-privilege attacker can exploit this to split a single malformed request into two forwarded requests and receive an additional smuggled response without needing a vulnerable server.
CVSS v3.1
Score 3.6low
Affected software
Progress Software
Progress® Telerik® Fiddler® Classic
pkg:github/telerik/fiddler-classicRun on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Progress Telerik Fiddler Classic for Windows versions before 6.0.20262.10021 contain an HTTP request/response smuggling vulnerability (CWE-444). The proxy component forwards HTTP requests that include both Content-Length and Transfer-Encoding headers without removing one, but internally frames the body using only Transfer-Encoding. This discrepancy causes desynchronization on reused client connections, allowing a local attacker with low privileges to craft a malformed request that is split into two separate requests forwarded to the origin server. The attacker can then receive an additional smuggled response. This vulnerability does not require the origin server to be vulnerable.
Potential Impact
An attacker with local low privileges can exploit this vulnerability to cause request desynchronization in the proxy, leading to the forwarding of two requests from a single malformed request and receiving an additional smuggled response. The confidentiality and integrity of data may be partially impacted (low impact), but there is no impact on availability. The CVSS 3.1 base score is 3.6 (low severity) reflecting limited impact and the requirement for local access with high attack complexity.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, avoid running vulnerable versions of Progress Telerik Fiddler Classic or restrict local access to trusted users only. Monitor vendor channels for updates and apply patches promptly once released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- ProgressSoftware
- Date Reserved
- 2026-08-21T13:37:32.974Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6ac3a0512cdf04f65600b116
Added to database: 10/05/2026, 13:04:17 UTC
Last enriched: 10/05/2026, 13:18:22 UTC
Last updated: 10/05/2026, 18:56:34 UTC
Views: 17
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.