VYPR

CloudFront

by Amazon

CVEs (2)

  • CVE-2020-36363CriAug 12, 2021
    risk 0.64cvss 9.8epss 0.01

    Amazon AWS CloudFront TLSv1.2_2019 allows TLS_ECDHE_RSA_WITH_AES_128_CBC_SHA256 and TLS_ECDHE_RSA_WITH_AES_256_CBC_SHA384, which some entities consider to be weak ciphers.

  • CVE-2026-13762CriJun 29, 2026
    risk 0.00cvss 9.8epss 0.00

    Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected. …