CVE-2026-13763: HTTP/2 Stream Parser Confusion Body-Inspection Bypass in AWS Application Load Balancer with AWS WAF
Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected. This issue only impacts HTTP/2 ALB target groups.
To remediate this issue, customers should enable the "Inspect after sufficient data" target group configuration associated to an ALB load balancer. Refer to: ( https://docs.aws.amazon.com/elasticloadbalancing/latest/application/edit-target-group-attributes.html#waf-http2-inspection )
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Enable the target group configuration option "Inspect after sufficient data" for HTTP/2 ALB target groups associated with your ALB load balancer so AWS WAF inspects after sufficient data is available.
AWS Application Load Balancer (ALB) target group with AWS WAF WAF HTTP/2 inspection - "Inspect after sufficient data" = enabled
Event History
Frequently Asked Questions
What is the severity of CVE-2026-13763?
CVE-2026-13763 has a critical severity score of 9.8.
How do I fix CVE-2026-13763?
To mitigate CVE-2026-13763, ensure that your AWS Application Load Balancer is configured to properly manage HTTP/2 requests and monitor for any unusual activity.
What systems are affected by CVE-2026-13763?
CVE-2026-13763 affects the Amazon Web Services Application Load Balancer that utilizes AWS WAF.
What is the risk associated with CVE-2026-13763?
CVE-2026-13763 poses a risk score of 86, indicating a significant potential for exploitation.
Can CVE-2026-13763 allow attackers to bypass security?
Yes, CVE-2026-13763 may allow remote actors to bypass AWS WAF managed rule body inspection through specially crafted HTTP/2 requests.