To remediate this issue, users should upgrade to version 0.8.2.
Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 31 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Jul 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured via HTTP_REQUEST_TOKEN_CONFIG by influencing the LLM to route requests through actor-controlled proxy infrastructure. To remediate this issue, users should upgrade to version 0.8.2. | |
| Title | Incorrect authorization in Strands Agents Tools http_request proxy credential exfiltration | |
| First Time appeared |
Aws
Aws strands Agents Tools |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:aws:strands_agents_tools:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws strands Agents Tools |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-07-31T20:01:07.095Z
Reserved: 2026-07-30T14:47:05.047Z
Link: CVE-2026-18394
Updated: 2026-07-31T20:00:59.895Z
No data.
No data.
OpenCVE Enrichment
No data.