Executive brief
AWS WAF is a web application firewall that protects customer applications from common web attacks. A flaw in how AWS WAF processes HTTP/2 multi-frame requests allows attackers to bypass request body inspection, potentially enabling malicious payloads to reach the protected application undetected.
Technical details
This vulnerability affects AWS WAF's ability to properly inspect request bodies in HTTP/2 multi-frame requests. The issue stems from improper handling of fragmented HTTP/2 frames when reconstructing the full request body for security inspection. An attacker can craft a specially-structured multi-frame HTTP/2 request that causes AWS WAF to fail to properly reassemble or inspect the request body, allowing bypass of WAF rules that would normally block malicious payloads. This requires network access to an application protected by AWS WAF and the ability to send crafted HTTP/2 requests. The impact is that web-based attacks (SQL injection, XSS, etc.) embedded in request bodies could bypass WAF protection. Patches are expected from AWS.
Affected products
- Amazon Web Services AWS WAF
Timeline
- 2026-09-22: disclosed