Strands Agents Tools Credential Leak via Proxy Bypass (CVE-2026-18394)
Strands Agents http_request tool has a critical authorization flaw affecting versions below 0.8.2. An attacker can inject prompts to redirect requests through a malicious proxy, exposing credentials in cleartext despite hostname allowlists. Update immediately to 0.8.2 or later—this requires your action.