CVE-2026-13763: HTTP/2 Stream Parser Confusion Body-Inspection Bypass in AWS Application Load Balancer with AWS WAF

Published Jun 29, 2026
·
Updated

Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected. This issue only impacts HTTP/2 ALB target groups.

To remediate this issue, customers should enable the "Inspect after sufficient data" target group configuration associated to an ALB load balancer. Refer to: ( https://docs.aws.amazon.com/elasticloadbalancing/latest/application/edit-target-group-attributes.html#waf-http2-inspection )

Affected Software

2 affected components
Amazon Web Services Application Load Balancer (ALB) with AWS WAF
Amazon Application Load Balancer

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Configuration

    Enable the target group configuration option "Inspect after sufficient data" for HTTP/2 ALB target groups associated with your ALB load balancer so AWS WAF inspects after sufficient data is available.

    AWS Application Load Balancer (ALB) target group with AWS WAF WAF HTTP/2 inspection - "Inspect after sufficient data" = enabled

Event History

Jun 29, 2026
CVE Published
via MITRE·08:03 PM
Data Sourced
via MITRE·08:03 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 PM
DescriptionSeverityWeaknessAffected Software
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-13763?

CVE-2026-13763 has a critical severity score of 9.8.

2

How do I fix CVE-2026-13763?

To mitigate CVE-2026-13763, ensure that your AWS Application Load Balancer is configured to properly manage HTTP/2 requests and monitor for any unusual activity.

3

What systems are affected by CVE-2026-13763?

CVE-2026-13763 affects the Amazon Web Services Application Load Balancer that utilizes AWS WAF.

4

What is the risk associated with CVE-2026-13763?

CVE-2026-13763 poses a risk score of 86, indicating a significant potential for exploitation.

5

Can CVE-2026-13763 allow attackers to bypass security?

Yes, CVE-2026-13763 may allow remote actors to bypass AWS WAF managed rule body inspection through specially crafted HTTP/2 requests.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203