
🛡️ AWS WAF bypass alert: CVE-2026-13763 lets attackers craft HTTP/2 requests that slip past AWS WAF body inspection on your ALB. No auth needed. Check your ALB target group attributes now. https://secalerts.co/vulnerability/CVE-2026-13763?utm_campaign=x https://t.co/HQN2y1rKz5
Post summary
The alert reports that CVE‑2026‑13763 allows unauthenticated attackers to craft HTTP/2 requests that bypass AWS WAF body inspection on an ALB, and recommends checking ALB target group attributes as a mitigation.



