In Progress® Telerik® Fiddler® Classic for Windows 版本早于 v6.0.20262.10021 时,在代理请求转发组件中存在 HTTP 请求走私漏洞。当请求包含多个值相互冲突的 Content-Length 头时,Fiddler 会将这些请求原封不动地转发给原始服务器,但其本身在构造请求体时仅使用第一个 Content-Length 的值。具备低权限的本地攻击者,若能通过另一个用户所使用的同一 Fiddler 代理实例发送请求,则可利用这种与原始服务器(该服务器不兼
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Progress Software | Progress® Telerik® Fiddler® Classic | 1.0.0 ~ 6.0.20262.10021 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92931 | 10.0 CRITICAL | CWE-918: Server-Side Request Forgery in the Progress Sitefinity Next.js Renderer SDK |
| CVE-2026-77805 | 7.9 HIGH | Weak Executable Signature Verification Vulnerability in Progress® Telerik® Fiddler® Classi |
| CVE-2026-77804 | 6.6 MEDIUM | Time-of-check Time-of-use (TOCTOU) Race Condition in Root Certificate Installation in Prog |
| CVE-2026-77803 | 3.6 LOW | Front-end Desynchronization Vulnerability in Progress® Telerik® Fiddler® Classic |
No comments yet