Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
7.9
CVE-2026-13762: AWS WAF may be bypassed by crafted HTTP/2 requests in CloudFront
CVE-2026-13762
Summary
AWS WAF managed rules might be bypassed if a hacker sends a special type of HTTP request. This issue has been fixed by AWS, so no action is needed from customers. Amazon CloudFront is a service that helps speed up websites and apps by storing them on edge servers around the world.
Original title
Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fr...
Original description
Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected.
This issue was remediated server-side. No customer action is required.
This issue was remediated server-side. No customer action is required.
nvd CVSS3.1
9.8
nvd CVSS4.0
7.9
Vulnerability type
CWE-444
Published: 29 Jun 2026 · Updated: 23 Jul 2026 · First seen: 29 Jun 2026