CVE-2026-13762Disclosure(amazon / cloudfront)

LOWCVSS 7.9 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected. This issue was remediated server-side. No customer action is required.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-444

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • cloudfront

Threat summary

  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 3 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • Peaked 2d ago at 1 mentions (2026-07-02); latest day: 1
  • 3 total mentions across 3 days

Affected systems

Vendors
Products
cloudfront

1 version affected across 1 product

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-07-02: 1Mentions · 2026-07-03: 1Mentions · 2026-07-04: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-03: 1Technical Details · 2026-07-04: 107-0207-0307-04
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-07-021
General1
2026-07-031
Disclosure1
2026-07-041
Disclosure1
Full discourse3 posts
  • SecAlerts@SecAlertsCo
    Disclosure

    ☁️ Amazon CloudFront + AWS WAF: crafted HTTP/2 requests can bypass WAF body inspection entirely. CVE-2026-13762 (CVSS 7.9) affects stream parser handling — no auth needed, network exploitable. Check your WAF rules now. https://secalerts.co/vulnerability/CVE-2026-13762?utm_campaign=x https://t.co/RbIo6OUJvc

    Post summary

    Amazon CloudFront and AWS WAF are vulnerable to CVE-2026-13762, enabling unauthenticated HTTP/2 request bypass of WAF body inspection; administrators are urged to review and update WAF rules.

    0000088
    847 followersView on X
  • Chris Short@ChrisShort
    Disclosure

    CVE-2026-13762 and CVE-2026-13763 - Issue with HTTP/2 multi-frame request body inspection in AWS WAF #devopsish https://aws.amazon.com/security/security-bulletins/2026-048-aws/

    Post summary

    AWS has released a security bulletin disclosing two CVEs affecting HTTP/2 body inspection in WAF, without mentioning PoC, exploits, or specific patches in the brief excerpt.

    00000176
    19.2K followersView on X
  • Eyal Estrin ☁️@eyalestrin
    General

    CVE-2026-13762 and CVE-2026-13763 - Issue with HTTP/2 multi-frame request body inspection in AWS WAF http://dlvr.it/TTKYM6 #patchmanagement

    Post summary

    The post references CVE‑2026‑13762 and CVE‑2026‑13763 as issues with HTTP/2 multi-frame request body inspection in AWS WAF, but does not provide information on exploitation, patches, or proof-of-concept details.

    0000044
    2.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appamazoncloudfront---

Explore more