CVE-2026-18394: Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured via HTTP_REQUEST_TOKEN_CONFIG by influencing the ...

Added to the CISA Known Exploited Vulnerabilities catalog on 31 Jul 2026. Vendor: AI/ML. Product: LLM. CVSS score: 7.4.

Incorrect authorization in the http_request tool in Strands Agents Tools before 0.8.2 might allow remote attackers to obtain credentials configured via HTTP_REQUEST_TOKEN_CONFIG by influencing the LLM to route requests through actor-controlled proxy infrastructure. To remediate this issue, use...

Required action: Review and patch if applicable to your AI infrastructure.