bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Monday, June 29, 2026

AWS WAF HTTP/2 Vulnerability: Action Needed for ALB Users

AWS WAF has patched two HTTP/2 multi-frame request body inspection vulnerabilities. CVE-2026-13762 (CloudFront) was fixed server-side—no action needed. CVE-2026-13763 (Application Load Balancer) requires your attention: crafted requests could bypass partial inspection. Configure your ALB's HTTP/2 body inspection settings to restore full protection.

> source: aws.amazon.com