Security Advisory Desk
unratedQCS priority 70/100Amazon Web Services

CVE-2026-13762 and CVE-2026-13763 - Issue with HTTP/2 multi-frame request body inspection in AWS WAF

Amazon Web Services discovered two issues in AWS WAF related to inspecting HTTP/2 multi-frame request bodies. One issue, CVE-2026-13762, affected AWS WAF with CloudFront and was fixed on the server side with no action needed from customers. The other, CVE-2026-13763, affected AWS WAF with Application Load Balancer (ALB) and could cause partial inspection of certain HTTP/2 request bodies. AWS released a configuration option on May 22, 2026, allowing customers to configure full inspection for HTTP/2 requests on ALB.

QCS published 10/10/2026, 12:26:36 am ISTVendor disclosure 9/10/2026, 11:49:17 pm ISTVerified 10/10/2026, 12:26:36 am ISTRevision 1

In plain language

What this advisory means

Amazon Web Services discovered two issues in AWS WAF related to inspecting HTTP/2 multi-frame request bodies. One issue, CVE-2026-13762, affected AWS WAF with CloudFront and was fixed on the server side with no action needed from customers. The other, CVE-2026-13763, affected AWS WAF with Application Load Balancer (ALB) and could cause partial inspection of certain HTTP/2 request bodies. AWS released a configuration option on May 22, 2026, allowing customers to configure full inspection for HTTP/2 requests on ALB.

Technical explanation

How the issue affects the environment

AWS WAF monitors HTTP(S) requests for protected web applications. Two vulnerabilities (CVE-2026-13762 and CVE-2026-13763) were identified affecting how AWS WAF inspects HTTP/2 multi-frame request bodies. CVE-2026-13762 impacted AWS WAF with CloudFront and was remediated fully server side. CVE-2026-13763 impacted AWS WAF on Application Load Balancer (ALB), where crafted multi-frame HTTP/2 requests could lead to only partial request body inspection. To address this, AWS introduced a new configuration option on ALB that accumulates HTTP/2 data frames before WAF inspection, ensuring full request body analysis. Customers must update their WAF inspection configuration under ALB target group attributes for HTTP/2 endpoints to enable this protection. No other workarounds are available.

Operational impact

Why teams should care

If customers did not update their AWS WAF inspection configuration for HTTP/2 on ALB, crafted HTTP/2 multi-frame requests might bypass full inspection, potentially reducing protection against certain web attacks. For AWS WAF with CloudFront, the issue was already remediated by AWS without customer action. Customers using ALB need to review and configure inspection settings to maintain proper defense, thereby managing risk to their web applications.

Immediate action

Customers using AWS WAF with AWS Application Load Balancer (ALB) should review and update their HTTP/2 traffic inspection behavior under the ALB target group attributes for HTTP/2 endpoints. This configuration enables ALB to accumulate HTTP/2 data frames before AWS WAF performs inspection, ensuring full request body analysis. AWS fixed the CloudFront-related issue server-side and requires no customer action there.

Affected and fixed releases

Affected versionsConfirm in the official vendor advisory
Fixed versionsConfirm in the official vendor advisory

Temporary risk reduction

No workarounds are available for these issues. The recommended resolution is to apply the updated ALB inspection configuration as provided by AWS.

Evidence and validation checklist

  • AWS Security Bulletins advisory published 2026-06-29
  • Description of CVE-2026-13762 and CVE-2026-13763 affecting HTTP/2 multi-frame inspection
  • Server-side remediation for CVE-2026-13762 (CloudFront)
  • Configuration option release date May 22, 2026 for ALB to address CVE-2026-13763
  • Recommendation for customers to update ALB WAF HTTP/2 inspection configuration
  • No workarounds available
  • Acknowledgment of coordinated disclosure with Korea University ISSLab researchers

Authoritative reference

AWS Security Bulletins

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source