Inconsistent interpretation of HTTP/2 requests in Amazon...
High severity
Unreviewed
Published
Jun 29, 2026
to the GitHub Advisory Database
Description
Published by the National Vulnerability Database
Jun 29, 2026
Published to the GitHub Advisory Database
Jun 29, 2026
Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body across frames so that only a partial body is inspected.
This issue was remediated server-side. No customer action is required.
References