CVE-2026-13763Disclosure(amazon / application_load_balancer)

LOWCVSS 7.9 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch amazon application_load_balancer systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected. This issue only impacts HTTP/2 ALB target groups. To remediate this issue, customers should enable the "Inspect after sufficient data" target group configuration associated to an ALB load balancer. Refer to: ( https://docs.aws.amazon.com/elasticloadbalancing/latest/application/edit-target-group-attributes.html#waf-http2-inspection )

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-444

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • application_load_balancer

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 3 classified signals
  • Peaked 3d ago at 1 mentions (2026-06-30); latest day: 1
  • 4 total mentions across 4 days

Affected systems

Vendors
Products
application_load_balancer

1 version affected across 1 product

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-06-30: 1Mentions · 2026-07-02: 1Mentions · 2026-07-03: 1Mentions · 2026-07-04: 1Patch / Workaround · 2026-06-30: 1Patch / Workaround · 2026-07-02: 1Patch / Workaround · 2026-07-04: 1Technical Details · 2026-06-30: 1Technical Details · 2026-07-02: 1Technical Details · 2026-07-03: 1Technical Details · 2026-07-04: 106-3007-0207-0307-04
Signal classification2 categories
Disclosure
375.0%
Patch
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-06-301
Disclosure1
2026-07-021
Patch1
2026-07-031
Disclosure1
2026-07-041
Disclosure1
Full discourse4 posts
  • SecAlerts@SecAlertsCo
    Disclosure

    🛡️ AWS WAF bypass alert: CVE-2026-13763 lets attackers craft HTTP/2 requests that slip past AWS WAF body inspection on your ALB. No auth needed. Check your ALB target group attributes now. https://secalerts.co/vulnerability/CVE-2026-13763?utm_campaign=x https://t.co/HQN2y1rKz5

    Post summary

    The alert reports that CVE‑2026‑13763 allows unauthenticated attackers to craft HTTP/2 requests that bypass AWS WAF body inspection on an ALB, and recommends checking ALB target group attributes as a mitigation.

    00000100
    847 followersView on X
  • Chris Short@ChrisShort
    Disclosure

    CVE-2026-13762 and CVE-2026-13763 - Issue with HTTP/2 multi-frame request body inspection in AWS WAF #devopsish https://aws.amazon.com/security/security-bulletins/2026-048-aws/

    Post summary

    The text announces two new AWS WAF CVEs tied to HTTP/2 request body inspection, pointing to an official AWS security bulletin for details.

    00000176
    19.2K followersView on X
  • Eyal Estrin ☁️@eyalestrin
    Patch

    CVE-2026-13762 and CVE-2026-13763 - Issue with HTTP/2 multi-frame request body inspection in AWS WAF http://dlvr.it/TTKYM6 #patchmanagement

    Post summary

    The post highlights CVE-2026-13762/13763 as an HTTP/2 request inspection flaw in AWS WAF and signals patch management, but offers no exploit details or active‑exploitation evidence.

    0000044
    2.0K followersView on X
  • Upwind Security MDR@UpwindMDR
    Disclosure

    🚨 High - AWS ALB + WAF HTTP/2 Body Inspection Bypass (CVE-2026-13763) AWS WAF deployments on AWS Application Load Balancer (ALB) can be affected by an HTTP/2 multi-frame request body inspection issue. Under certain conditions, a crafted HTTP/2 request that splits the body across multiple data frames may cause AWS WAF to inspect only a partial request body, potentially allowing malicious payloads to bypass WAF body-inspection rules and reach the backend. The issue affects AWS WAF on ALB when routing to HTTP/2 targets. There is no customer-side software version to patch, as this is an AWS-managed service; AWS addressed the issue on ALB and recommends updating the WAF HTTP/2 inspection behavior in the ALB target group attributes. Remediation: set the ALB target group’s WAF HTTP/2 traffic inspection behavior to “Inspect after sufficient data” for standard request-response applications.

    Post summary

    AWS announced a high‑severity HTTP/2 body inspection bypass in WAF on ALB, detailing the flaw and providing a remediation step to update target group inspection settings.

    0000096
    232 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appamazonapplication_load_balancer---

Explore more