VYPR
Critical severity9.8NVD Advisory· Published Jun 29, 2026· Updated Jul 1, 2026

CVE-2026-13762

CVE-2026-13762

Description

Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected.

This issue was remediated server-side. No customer action is required.

Affected products

3
  • Amazon/CloudFront2 versions
    cpe:2.3:a:amazon:cloudfront:-:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:amazon:cloudfront:-:*:*:*:*:*:*:*
    • (no CPE)
  • AWS/WAFllm-fuzzy

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.