CVE-2026-18394 - Incorrect authorization in Strands Agents Tools http_request tool
Bulletin ID: 2026-069-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/31/2026 12:30 PM PDT Description: Strands Agents is an open-source SDK for building AI agents. The strands-agents-tools package provides pre-built tools for use with the SDK, including the http_request tool for making HTTP API requests. We identified CVE-2026-18394, an incorrect authorization issue in the http_request tool. Operators can use the HTTP_REQUEST_TOKEN_CONFIG allowlist to bind a credential to a set of approved hostnames so it is sent only to those hosts. The tool also exposed a proxies parameter in the input schema that the large language model (LLM) could control. A crafted prompt, for example one delivered through untrusted web content the agent reads (indirect prompt injection), could set proxies to an actor-controlled endpoint. The hostname allowlist check still passes on the request URL, the credential is attached, and the request is routed through the actor's proxy on the first hop, disclosing the credential in cleartext in the Authorization header. Impacted versions: < 0.8.2 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Details
Original advisory: https://aws.amazon.com/security/security-bulletins/rss/2026-069-aws/
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-18394 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
Recent advisories for - Incorrect authorization
A cluster of recent advisories against the same product widens the attack surface — attackers routinely chain freshly published CVEs on one product, so review these together.
- mediumCVE-2026-11995: The Gutena Forms – Contact Form, Survey Form, Feedback Form, Booking Form, and Custom Form Bui…nvd · 2026-08-01
- mediumCVE-2026-10782: The RealHomes Memberships plugin for WordPress is vulnerable to authorization bypass in all ve…nvd · 2026-08-01
- unknownCVE-2026-14839: The Mapster WP Maps WordPress plugin before 1.24.0 does not perform any authorization or post-…nvd · 2026-08-01
- unknownCVE-2026-14823: The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not properly verify a…nvd · 2026-08-01
- unknownCVE-2026-14822: The Event Tickets and Registration WordPress plugin before 5.29.0.1 does not perform any autho…nvd · 2026-08-01
- unknownCVE-2026-14315: The Pixel Tag Manager for WooCommerce WordPress plugin before 2.2.1 does not perform an author…nvd · 2026-08-01
More from AWS Security Bulletins
- unknownCVE-2026-18420 - Remote Code Execution via Prototype Pollution in OpenSearch Dashboards TSVB Plugin2026-07-31
- unknownIncomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-react2026-07-31
- unknownCVE-2026-18140 - Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated re…2026-07-31
- unknownCVE-2026-16796 - Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_pa…2026-07-23
- unknownCVE-2026-16756 - Allocation of resources without limits in the default aws-smithy-http-server serve() path all…2026-07-23