VYPR

Telerik Fiddler Classic

by Progress (organisation)

CVEs (4)

  • CVE-2026-77805HigOct 5, 2026
    risk 0.51cvss 7.9epss —

    In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, the integrity check applied to the external helper tools launched by the application is insufficient. Before executing a helper tool, the application only verifies that the file carries a…

  • CVE-2026-77804MedOct 5, 2026
    risk 0.43cvss 6.6epss —

    In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, a time-of-check time-of-use (TOCTOU) race condition exists in the installation of the HTTPS interception root certificate into the Local Computer certificate store. Fiddler writes the…

  • CVE-2026-77802MedOct 5, 2026
    risk 0.41cvss 6.3epss —

    In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, HTTP request smuggling is possible in the proxy request forwarding component. Requests containing multiple Content-Length headers with conflicting values are forwarded verbatim to the…

  • CVE-2026-77803LowOct 5, 2026
    risk 0.23cvss 3.6epss —

    In Progress® Telerik® Fiddler® Classic for Windows, versions prior to v6.0.20262.10021, front-end request desynchronization is possible in the proxy request forwarding component. A request that contains both a Content-Length and a Transfer-Encoding header is forwarded with…