Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.9

CVE-2026-13762: AWS WAF may be bypassed by crafted HTTP/2 requests in CloudFront

CVE-2026-13762
Summary

AWS WAF managed rules might be bypassed if a hacker sends a special type of HTTP request. This issue has been fixed by AWS, so no action is needed from customers. Amazon CloudFront is a service that helps speed up websites and apps by storing them on edge servers around the world.

Original title
Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fr...
Original description
Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected.



This issue was remediated server-side. No customer action is required.
nvd CVSS3.1 9.8
nvd CVSS4.0 7.9
Vulnerability type
CWE-444
Published: 29 Jun 2026 · Updated: 23 Jul 2026 · First seen: 29 Jun 2026