在适用于 Windows 的 In Progress® Telerik® Fiddler® Classic 中,v6.0.20262.10021 之前的版本在代理请求转发组件中存在前端请求不同步漏洞。当一个请求同时包含 Content-Length 和 Transfer-Encoding 标头时,Fiddler 在转发请求时会同时保留这两个标头,但在内部对请求体使用 Transfer-Encoding 进行封装。复用客户端连接时,剩余的字节会被解析为一个独立的流水线化(pipelined)请求。因此,本地具有低权限
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Progress Software | Progress® Telerik® Fiddler® Classic | 1.0.0 ~ 6.0.20262.10021 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-92931 | 8.8 HIGH | CWE-918: Server-Side Request Forgery in the Progress Sitefinity Next.js Renderer SDK |
| CVE-2026-77805 | 7.9 HIGH | Weak Executable Signature Verification Vulnerability in Progress® Telerik® Fiddler® Classi |
| CVE-2026-77804 | 6.6 MEDIUM | Time-of-check Time-of-use (TOCTOU) Race Condition in Root Certificate Installation in Prog |
| CVE-2026-77802 | 6.3 MEDIUM | HTTP Request Smuggling Vulnerability in Progress® Telerik® Fiddler® Classic |
No comments yet