Issue with HTTP/2 multi-frame request body inspection in AWS WAF
Critical9.8CVE-2026-13762 · Published Sep 22, 2026
Bulletin ID: 2026-048-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/29/2026 13:15 PM PDT Description: AWS WAF is a web application firewall that monitors the HTTP(S) requests that are forwarded to your protected web application resources. We identified CVE-2026-13762 and CVE-2026-13763 , which are issues affecting HTTP/2 multi-frame request body inspection by AWS WAF. CVE-2026-13762 affects AWS WAF deployment with CloudFront. This issue was remediated server-side; no customer action is required. CVE-2026-13763 affects AWS WAF deployment with AWS Application Load Balancer (ALB). Under certain conditions, a crafted multi-frame HTTP/2 request could cause only a partial request body to be inspected. This issue has been addressed on ALB, and customers can ensure full protection by configuring how AWS WAF inspects HTTP/2 request bodies on their ALB. Resolution: On May 22, 2026, we released a new configuration option on ALB, which addresses this issue. We recommend that customers review and update the WAF HTTP/2 traffic inspection behavior under target group attributes for HTTP/2 endpoints. This enables ALB to accumulate HTTP/2 da...
Affected versions
Changes since it was listed
| Date | Change |
|---|---|
| Sep 26 | Severity: Unrated to Critical |
Details and references
Bulletin ID: 2026-048-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/29/2026 13:15 PM PDT Description: AWS WAF is a web application firewall that monitors the HTTP(S) requests that are forwarded to your protected web application resources. We identified CVE-2026-13762 and CVE-2026-13763 , which are issues affecting HTTP/2 multi-frame request body inspection by AWS WAF. CVE-2026-13762 affects AWS WAF deployment with CloudFront. This issue was remediated server-side; no customer action is required. CVE-2026-13763 affects AWS WAF deployment with AWS Application Load Balancer (ALB). Under certain conditions, a crafted multi-frame HTTP/2 request could cause only a partial request body to be inspected. This issue has been addressed on ALB, and customers can ensure full protection by configuring how AWS WAF inspects HTTP/2 request bodies on their ALB. Resolution: On May 22, 2026, we released a new configuration option on ALB, which addresses this issue. We recommend that customers review and update the WAF HTTP/2 traffic inspection behavior under target group attributes for HTTP/2 endpoints. This enables ALB to accumulate HTTP/2 data frames before AWS WAF performs inspection. For detailed instructions, refer to the developer guide . Workarounds: No workarounds are available. References: CVE-2026-13762 CVE-2026-13763 Acknowledgement: We would like to thank Kyungrok Choi, Woonghee Lee, and Junbeom Hur from Korea University ISSLab for collaborating on these issues through the coordinated vulnerability disclosure process. Please email aws-security@amazon.com with any security questions or concerns. "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-048-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-13762 and CVE-2026-13763 - Issue with HTTP/2 multi-frame request body inspection in AWS WAF Bulletin ID: 2026-048-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 06/29/2026 13:15 PM PDT Description: AWS WAF is a web application firewall that monitors the HTTP(S) requests that are forwarded to your protected web application resources. We identified CVE-2026-13762 and CVE-2026-13763 , which are issues affecting HTTP/2 multi-frame request body inspection by AWS WAF. CVE-2026-13762 affects AWS WAF deployment with CloudFront. This issue was remediated server-side; no customer action is required. CVE-2026-13763 affects AWS WAF deployment with AWS Application Load Balancer (ALB). Under certain conditions, a crafted multi-frame HTTP/2 request could cause only a partial request body to be inspected. This issue has been addressed on ALB, and customers can ensure full protection by configuring how AWS WAF inspects HTTP/2 request bodies on their ALB. Resolution: On May 22, 2026, we released a new configuration option on ALB, which addresses this issue. We recommend that customers review and update the WAF HTTP/2 traffic inspection behavior under target group attributes for HTTP/2 endpoints. This enables ALB to accumulate HTTP/2 data frames before AWS WAF performs inspection. For detailed instructions, refer to the developer guide . Worka
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- NVD
- Also known as
- CVE-2026-13763
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 22 | Kiro IDE Insufficient File Write Restrictions to Execution-Sensitive Paths | High8.8 | No fix yet |
| Sep 22 | Amazon Aurora PostgreSQL a fully managed relational database engine that's compatible... | High8.0 | No fix yet |
| Sep 22 | HTTPS Fallback to HTTP in Graph Explorer | Medium5.9 | No fix yet |
| Sep 22 | Code Injection via Improper Triple-Quote Escaping in AgentCore CLI Bedrock Agent Import | Critical9.0 | No fix yet |
| Sep 22 | Authenticated SQL injection in the metrics-service retention policy subsystem of... | High8.1 | No fix yet |
| Sep 22 | Excessive memory allocation in s2n-quic | Medium5.3 | No fix yet |