Skip to content
AWSAWS-2026-048

Issue with HTTP/2 multi-frame request body inspection in AWS WAF

Critical9.8CVE-2026-13762 · Published Sep 22, 2026

Bulletin ID:  2026-048-AWS Scope:  AWS Content Type:  Important (requires attention) Publication Date:  06/29/2026 13:15 PM PDT Description: AWS WAF is a web application firewall that monitors the HTTP(S) requests that are forwarded to your protected web application resources. We identified CVE-2026-13762 and CVE-2026-13763 , which are issues affecting HTTP/2 multi-frame request body inspection by AWS WAF. CVE-2026-13762 affects AWS WAF deployment with CloudFront. This issue was remediated server-side; no customer action is required. CVE-2026-13763 affects AWS WAF deployment with AWS Application Load Balancer (ALB). Under certain conditions, a crafted multi-frame HTTP/2 request could cause only a partial request body to be inspected. This issue has been addressed on ALB, and customers can ensure full protection by configuring how AWS WAF inspects HTTP/2 request bodies on their ALB. Resolution: On May 22, 2026, we released a new configuration option on ALB, which addresses this issue. We recommend that customers review and update the WAF HTTP/2 traffic inspection behavior under target group attributes for HTTP/2 endpoints. This enables ALB to accumulate HTTP/2 da...

AWS advisory

Affected versions

The source does not list versions here. See the source advisory for affected products and fixes.

Changes since it was listed

DateChange
Sep 26Severity: Unrated to Critical
Details and references

Bulletin ID:  2026-048-AWS Scope:  AWS Content Type:  Important (requires attention) Publication Date:  06/29/2026 13:15 PM PDT Description: AWS WAF is a web application firewall that monitors the HTTP(S) requests that are forwarded to your protected web application resources. We identified CVE-2026-13762 and CVE-2026-13763 , which are issues affecting HTTP/2 multi-frame request body inspection by AWS WAF. CVE-2026-13762 affects AWS WAF deployment with CloudFront. This issue was remediated server-side; no customer action is required. CVE-2026-13763 affects AWS WAF deployment with AWS Application Load Balancer (ALB). Under certain conditions, a crafted multi-frame HTTP/2 request could cause only a partial request body to be inspected. This issue has been addressed on ALB, and customers can ensure full protection by configuring how AWS WAF inspects HTTP/2 request bodies on their ALB. Resolution: On May 22, 2026, we released a new configuration option on ALB, which addresses this issue. We recommend that customers review and update the WAF HTTP/2 traffic inspection behavior under target group attributes for HTTP/2 endpoints. This enables ALB to accumulate HTTP/2 data frames before AWS WAF performs inspection. For detailed instructions, refer to the developer guide . Workarounds: No workarounds are available. References: CVE-2026-13762 CVE-2026-13763 Acknowledgement: We would like to thank Kyungrok Choi, Woonghee Lee, and Junbeom Hur from Korea University ISSLab for collaborating on these issues through the coordinated vulnerability disclosure process. Please email  aws-security@amazon.com  with any security questions or concerns.   "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-048-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-13762 and CVE-2026-13763 - Issue with HTTP/2 multi-frame request body inspection in AWS WAF Bulletin ID:  2026-048-AWS Scope:  AWS Content Type:  Important (requires attention) Publication Date:  06/29/2026 13:15 PM PDT Description: AWS WAF is a web application firewall that monitors the HTTP(S) requests that are forwarded to your protected web application resources. We identified CVE-2026-13762 and CVE-2026-13763 , which are issues affecting HTTP/2 multi-frame request body inspection by AWS WAF. CVE-2026-13762 affects AWS WAF deployment with CloudFront. This issue was remediated server-side; no customer action is required. CVE-2026-13763 affects AWS WAF deployment with AWS Application Load Balancer (ALB). Under certain conditions, a crafted multi-frame HTTP/2 request could cause only a partial request body to be inspected. This issue has been addressed on ALB, and customers can ensure full protection by configuring how AWS WAF inspects HTTP/2 request bodies on their ALB. Resolution: On May 22, 2026, we released a new configuration option on ALB, which addresses this issue. We recommend that customers review and update the WAF HTTP/2 traffic inspection behavior under target group attributes for HTTP/2 endpoints. This enables ALB to accumulate HTTP/2 data frames before AWS WAF performs inspection. For detailed instructions, refer to the developer guide . Worka

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
NVD
Also known as
CVE-2026-13763

More AWS advisories

All AWS
Advisory
Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths
High8.8Sep 22
Amazon Aurora PostgreSQL a fully managed relational database engine that's compatible...
High8.0Sep 22
HTTPS Fallback to HTTP in Graph Explorer
Medium5.9Sep 22
Code Injection via Improper Triple-Quote Escaping in AgentCore CLI Bedrock Agent Import
Critical9.0Sep 22
Authenticated SQL injection in the metrics-service retention policy subsystem of...
High8.1Sep 22
Excessive memory allocation in s2n-quic
Medium5.3Sep 22

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.