Strands Agents Tools 0.8.2: http_request tool Insecure Authorization
CVE-2026-18394 Published on July 31, 2026
Incorrect authorization in Strands Agents Tools http_request proxy credential exfiltration
Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured via HTTP_REQUEST_TOKEN_CONFIG by influencing the LLM to route requests through actor-controlled proxy infrastructure.
To remediate this issue, users should upgrade to version 0.8.2.
Vulnerability Analysis
CVE-2026-18394 is exploitable with network access, requires user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity and availability.
Weakness Type
What is an AuthZ Vulnerability?
The software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.
CVE-2026-18394 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-18394
stack.watch emails you whenever new vulnerabilities are published in Amazon Aws or Aws Strands Agents Tools. Just hit a watch button to start following.
Affected Versions
AWS Strands Agents Tools:- Before 0.8.2 is affected.