CVE-2026-13762: HTTP/2 Stream Parser Confusion Body-Inspection Bypass in Amazon CloudFront with AWS WAF
Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected.
This issue was remediated server-side. No customer action is required.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13762?
The severity of CVE-2026-13762 is rated as high with a score of 7.9.
How do I fix CVE-2026-13762?
To remediate CVE-2026-13762, ensure that you have the latest updates and configurations applied to Amazon CloudFront and AWS WAF.
What is CVE-2026-13762 in Amazon CloudFront?
CVE-2026-13762 is a vulnerability that allows remote actors to bypass AWS WAF managed rule body inspection through crafted HTTP/2 requests.
What can attackers do with CVE-2026-13762?
Attackers can exploit CVE-2026-13762 to bypass body inspection mechanisms, potentially leading to the delivery of malicious payloads.
Is CVE-2026-13762 related to HTTP/2 requests?
Yes, CVE-2026-13762 specifically pertains to the inconsistent interpretation of HTTP/2 requests in Amazon CloudFront.