Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
7.9

CVE-2026-13763: AWS Load Balancer: HTTP/2 Bypass of WAF Inspection

CVE-2026-13763
Summary

Some AWS load balancers might not properly check requests if they use a new internet protocol. This can let hackers get past security rules. To fix this, make sure your load balancer is set to inspect requests fully, as described in the AWS documentation.

Original title
Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requ...
Original description
Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected. This issue only impacts HTTP/2 ALB target groups.



To remediate this issue, customers should enable the "Inspect after sufficient data" target group configuration associated to an ALB load balancer. Refer to: ( https://docs.aws.amazon.com/elasticloadbalancing/latest/application/edit-target-group-attributes.html#waf-http2-inspection )
nvd CVSS3.1 9.8
nvd CVSS4.0 7.9
Vulnerability type
CWE-444
Published: 29 Jun 2026 · Updated: 23 Jul 2026 · First seen: 29 Jun 2026