CyberRota
← Ana sayfaya dön

CVE-2026-13763

CRITICAL · CVSS 9.8 EPSS %0.50

Kaynak: NVD + CISA KEV + EPSS · Yayınlanma: 2026-06-29T20:17:33.283 · Çekilme zamanı: 2026-06-30T18:37:31.478568+00:00

CyberRota Yorumu

Uzaktan istismar edilebilir olabilir.

CVE
CVE-2026-13763
Severity
CRITICAL
CVSS
9.8
EPSS
%0.50

Orijinal NVD Açıklaması

Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected. This issue only impacts HTTP/2 ALB target groups. To remediate this issue, customers should enable the "Inspect after sufficient data" target group configuration associated to an ALB load balancer. Refer to: ( https://docs.aws.amazon.com/elasticloadbalancing/latest/application/edit-target-group-attributes.html#waf-http2-inspection )