CVE-2026-13763
HTTP/2 Stream Parser Confusion Body-Inspection Bypass in AWS Application Load Balancer with AWS WAF
Description
Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected. This issue only impacts HTTP/2 ALB target groups. To remediate this issue, customers should enable the "Inspect after sufficient data" target group configuration associated to an ALB load balancer. Refer to: ( https://docs.aws.amazon.com/elasticloadbalancing/latest/application/edit-target-group-attributes.html#waf-http2-inspection )
In plain language
AI Worth attentionThis is a flaw in AWS Application Load Balancer’s HTTP/2 handling that can let attackers slip malicious content past AWS WAF inspection; if you use ALB with AWS WAF over HTTP/2, you should review and adjust your WAF/HTTP/2 inspection settings now.
An HTTP/2 stream parsing weakness (CWE-444) in AWS Application Load Balancer can bypass AWS WAF managed rule body inspection by having the request body split across HTTP/2 frames so WAF inspects only a partial body; this is triggered by a remote, unauthenticated HTTP/2 request to an ALB endpoint with AWS WAF enabled.
What to do now
- Confirm whether your AWS Application Load Balancer is configured with AWS WAF enabled and uses HTTP/2.
- For the affected HTTP/2 setup (ALB target groups), verify your target group WAF/HTTP2 inspection behavior.
- Enable the “Inspect after sufficient data” target group configuration associated with your ALB load balancer (per AWS guidance) to force WAF inspection after enough request data is received.
- Test your application paths behind the ALB with normal traffic patterns and monitor AWS WAF logs for unexpected decreases in inspection effectiveness or blocked requests.
CVSS Vector Breakdown
AV:NAttack VectorAC:LAttack ComplexityPR:NPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-13763 and every CVE in our database. Create a free account — no credit card required.
Create Free Account