CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-13763

criticalCVSS 9.8covered by 2 sourcesfirst seen 2026-06-29
Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected. This issue only impacts HTTP/2 ALB target groups. To remediate this issue, customers should enable the "Inspect after sufficient data" target group configuration associated to an ALB load balancer. Refer to: ( https://docs.aws.amazon.com/elasticloadbalancing/latest/application/edit-target-group-attributes.html#waf-http2-inspection )

CSIRTS triage

What
Issues with HTTP/2 multi-frame request body inspection in AWS WAF could lead to incomplete request body processing.
Who is affected
AWS WAF deployments with Application Load Balancer (ALB) are affected.
Urgency
Remediation is important to ensure full protection against crafted requests.
Action
Configure AWS WAF to properly inspect HTTP/2 request bodies on ALB.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-13763

Get an email if CVE-2026-13763 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-13763

CVE.org record

Embed the live status

CVE-2026-13763 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-13763 status](https://www.csirts.com/badge/CVE-2026-13763)](https://www.csirts.com/cve/CVE-2026-13763)