Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured via HTTP_REQUEST_TOKEN_CONFIG by influencing the LLM to route requests through actor-controlled proxy infrastructure.
To remediate this issue, users should upgrade to version 0.8.2.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-31 20:16
Updated : 2026-08-04 14:48
NVD link : CVE-2026-18394
Mitre link : CVE-2026-18394
CVE.ORG link : CVE-2026-18394
JSON object : View
Products Affected
No product.
CWE
CWE-863
Incorrect Authorization
