Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured via HTTP_REQUEST_TOKEN_CONFIG by influencing the LLM to route requests through actor-controlled proxy infrastructure.
To remediate this issue, users should upgrade to version 0.8.2.
Metrics
Affected Vendors & Products
References
History
Fri, 31 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Jul 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured via HTTP_REQUEST_TOKEN_CONFIG by influencing the LLM to route requests through actor-controlled proxy infrastructure. To remediate this issue, users should upgrade to version 0.8.2. | |
| Title | Incorrect authorization in Strands Agents Tools http_request proxy credential exfiltration | |
| First Time appeared |
Aws
Aws strands Agents Tools |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:aws:strands_agents_tools:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws strands Agents Tools |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-07-31T20:01:07.095Z
Reserved: 2026-07-30T14:47:05.047Z
Link: CVE-2026-18394
Updated: 2026-07-31T20:00:59.895Z
No data.
No data.
OpenCVE Enrichment
No data.