
☁️ Amazon CloudFront + AWS WAF: crafted HTTP/2 requests can bypass WAF body inspection entirely. CVE-2026-13762 (CVSS 7.9) affects stream parser handling — no auth needed, network exploitable. Check your WAF rules now. https://secalerts.co/vulnerability/CVE-2026-13762?utm_campaign=x https://t.co/RbIo6OUJvc
Post summary
Amazon CloudFront and AWS WAF are vulnerable to CVE-2026-13762, enabling unauthenticated HTTP/2 request bypass of WAF body inspection; administrators are urged to review and update WAF rules.


