To remediate this issue, users should upgrade to version 0.8.2.
Metrics
Affected Vendors & Products
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 31 Jul 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Jul 2026 19:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured via HTTP_REQUEST_TOKEN_CONFIG by influencing the LLM to route requests through actor-controlled proxy infrastructure. To remediate this issue, users should upgrade to version 0.8.2. | |
| Title | Incorrect authorization in Strands Agents Tools http_request proxy credential exfiltration | |
| First Time appeared |
Aws
Aws strands Agents Tools |
|
| Weaknesses | CWE-863 | |
| CPEs | cpe:2.3:a:aws:strands_agents_tools:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws strands Agents Tools |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-07-31T20:01:07.095Z
Reserved: 2026-07-30T14:47:05.047Z
Link: CVE-2026-18394
Updated: 2026-07-31T20:00:59.895Z
Status : Awaiting Analysis
Published: 2026-07-31T20:16:49.780
Modified: 2026-08-04T14:48:22.933
Link: CVE-2026-18394
No data.
OpenCVE Enrichment
Updated: 2026-08-03T10:00:12Z