Strands Agents Tools 0.8.2: http_request tool Insecure Authorization
CVE-2026-18394 Published on July 31, 2026

Incorrect authorization in Strands Agents Tools http_request proxy credential exfiltration
Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured via HTTP_REQUEST_TOKEN_CONFIG by influencing the LLM to route requests through actor-controlled proxy infrastructure. To remediate this issue, users should upgrade to version 0.8.2.

Vendor Advisory NVD

Vulnerability Analysis

CVE-2026-18394 is exploitable with network access, requires user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.

Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
REQUIRED
Scope:
CHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
NONE
Availability Impact:
NONE

Weakness Type

What is an AuthZ Vulnerability?

The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.

CVE-2026-18394 has been classified to as an AuthZ vulnerability or weakness.


Products Associated with CVE-2026-18394

stack.watch emails you whenever new vulnerabilities are published in Amazon Aws or Aws Strands Agents Tools. Just hit a watch button to start following.

 
 

Affected Versions

AWS Strands Agents Tools: