CloudfrontApplication · Amazon

CVE-2026-13762

CRITICAL · 9.8 CVSS v3.1 Published 2026-06-29
Mitigation only
No fix yet — a mitigation exists. There is no fixed release. A documented workaround reduces exposure in the meantime.
See remediation →
100/100
Remediation priority · Urgent
Remotely reachable No privileges Zero-click 8 weeks old

Official description Straight from the sourceThe vendor's or NVD's own wording, published unedited. Authoritative, but often terse — it says what broke, rarely what to do.

NVD · unedited
Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected. This issue was remediated server-side. No customer action is required.

Technical summary Written by usOur analysis, written from the advisory, the CVSS vector and the affected-version data. It adds context the advisory leaves out, and never invents facts that are not in the source.

dbcve analysis · high confidence

In CloudFront with AWS WAF enabled, HTTP/2 requests with body content fragmented across multiple frames can cause inconsistent body inspection - WAF only examines partial body content, allowing attackers to bypass managed rule body inspection by splitting malicious payloads across frames.

MitigationNo customer action required. AWS has remediated this vulnerability server-side. Ensure CloudFront distributions are using current service configurations.

Verify against the referenced sources before acting — the references below are authoritative for this CVE, this summary is not.

Affected products & versions What the vendor confirmedThe version ranges the vendor confirmed as vulnerable. If your version sits inside a range here, treat yourself as exposed until you have upgraded.

NVD · CPE data
CloudfrontApplication
Affected:all versions

CVSS breakdown How the score is builtThe industry scoring standard. It rates how the flaw is reached, what it takes to exploit, and what an attacker gains — the score is derived from those, not the other way round.

From the vector
Attack vector
Network
Complexity
Low
Privileges
None
User interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Am I affected? How to checkSteps we derive from the advisory and the affected-version data, so you can decide whether this CVE reaches your setup. They are a guide, not a scan — your own configuration is the authority.

dbcve checks

Work through these to decide whether this CVE applies to you.

  1. Verify WAF body inspection is enabled
    In the AWS WAF console, navigate to your web ACL and inspect the rule groups. Check if any rules have 'Inspect request body' configured, or use AWS CLI: aws wafv2 get-web-acl --name <acl-name> --scope CLOUDFRONT --region us-east-1 --query 'Rules[].Statement[].ByteMatchStatement' or similar for body inspection rules.
    Affected if WAF is configured to inspect HTTP request bodies - this was the attack surface for this bypass.
  2. Review WAF logs for partial body patterns
    In AWS CloudWatch or your configured logging destination, query WAF logs for requests where Request.BodyAvailable is false or where the logged body size is unexpectedly small compared to expected payloads. Look for patterns: aws logs filter-log-events --log-group-name aws-waf-logs-<acl-name> --filter-pattern 'Request.BodyAvailable false'
    Affected if Logs show requests with incomplete body inspection during the vulnerability window (dates unknown but server-side fix applied).
  3. Search for HTTP/2 fragmented request anomalies
    Query WAF logs for HTTP/2 requests with unusual frame counts or sizes. Check for requests where the logged request body does not match Content-Length header. Use: aws logs filter-log-group --log-group-name aws-waf-logs-<acl-name> --filter-pattern 'Protocol HTTP/2'
    Affected if Multiple HTTP/2 frames were logged for single requests or Content-Length mismatches exist, indicating potential fragmentation exploitation.
  4. Identify rules that may have been evaded
    In AWS WAF console, review rules set to block or count based on body content (SQL injection, XSS, etc.). Cross-reference their action counts during the vulnerability window against baseline expectations. Check CloudTrail for any suspicious rule configuration changes.
    Affected if Block/count counts for body-inspecting rules dropped unexpectedly or rule actions were unexpectedly skipped during the vulnerability period.

You were affected if you had AWS WAF configured with body inspection rules on CloudFront during the vulnerability window and now need to review logs for potential bypass indicators, though Amazon has already server-side patched this issue.

Generated from the published advisory. Verify against your own configuration.

Check your environment

Paste your version and any relevant configuration and it will be compared against the affected criteria above. Do not include secrets or credentials.

AI-assisted, checked against the advisory. Informational, not a guarantee.

Remediation Closing itWhat it takes to close this. Where a vendor fix exists we point at it; where none exists we say so plainly, and can build one. Effort estimates are scoped from the advisory, not from your codebase.

From vendor data
Mitigation available No clean upgrade yet — mitigate in the meantime
Mitigation

No customer action required. AWS has remediated this vulnerability server-side. Ensure CloudFront distributions are using current service configurations.

Fix this in Cloudfront Scoped from the published advisory
  • Consultation1.0 h
  • Testing2.0 h
  • Review / QA1.0 h
4.0 hours of engineering $750
Get help mitigating

An estimate, not a bill — we confirm scope with you before any work starts. Need it this week? Rush from $1,200.

Scan for this in your stack

Free · runs locally
dbcve dependency scanner

Check whether your project pulls in CVE-2026-13762 — or any other known-vulnerable package — straight from your lock files. Free and open source; it runs locally and uploads nothing.

References Go to the primary sourcePrimary sources — vendor advisories, patches and trackers. Where our summary and a reference disagree, the reference wins.

Primary sources

Practitioner notes

Contributed

Peer-ranked notes from engineers who’ve handled CVE-2026-13762 in production — separate from our analysis above.

No notes yet

Be the first to add a field note for this CVE — a mitigation you’ve verified, a version caveat, or a link to a working fix. Sign in above to contribute.

What this is

A place for practitioners to share what actually worked: a mitigation you’ve tested, a configuration change, a version- or environment-specific caveat, or a link to a verified patch. The most useful notes rise to the top as peers upvote them, so the signal stays high.

What belongs here
  • Verified mitigations, workarounds, and config changes
  • Version or environment caveats, and links to real fixes
  • No weaponised exploit code, or anything meant to cause harm
  • No spam, self-promotion, credentials, or personal data