CVE-2026-18394

Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured via HTTP_REQUEST_TOKEN_CONFIG by influencing the LLM to route requests through actor-controlled proxy infrastructure. To remediate this issue, users should upgrade to version 0.8.2.
Configurations

No configuration.

History

No history.

Information

Published : 2026-07-31 20:16

Updated : 2026-08-04 14:48


NVD link : CVE-2026-18394

Mitre link : CVE-2026-18394

CVE.ORG link : CVE-2026-18394


JSON object : View

Products Affected

No product.

CWE
CWE-863

Incorrect Authorization