CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-13762

criticalCVSS 9.8covered by 2 sourcesfirst seen 2026-06-29
Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected. This issue was remediated server-side. No customer action is required.

CSIRTS triage

What
Issues with HTTP/2 multi-frame request body inspection in AWS WAF could lead to incomplete request body processing.
Who is affected
AWS WAF deployments with Application Load Balancer (ALB) are affected.
Urgency
Remediation is important to ensure full protection against crafted requests.
Action
Configure AWS WAF to properly inspect HTTP/2 request bodies on ALB.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-13762

Get an email if CVE-2026-13762 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-13762

CVE.org record

Embed the live status

CVE-2026-13762 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-13762 status](https://www.csirts.com/badge/CVE-2026-13762)](https://www.csirts.com/cve/CVE-2026-13762)