bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Friday, July 31, 2026

Strands Agents Tools Credential Leak via Proxy Bypass (CVE-2026-18394)

Strands Agents http_request tool has a critical authorization flaw affecting versions below 0.8.2. An attacker can inject prompts to redirect requests through a malicious proxy, exposing credentials in cleartext despite hostname allowlists. Update immediately to 0.8.2 or later—this requires your action.

> source: aws.amazon.com