CVE-2026-18394 - Incorrect authorization in Strands Agents Tools http_request tool

Published 2026-08-20T21:35:57Z61671c9aac485bf157d4e9a44b7e150b0228b6a68fd945528f2dea7933124d3b

Source metadata

Publication date
2026-08-20T21:35:57Z
Source identifier
962df9ae3fdd8e7da1c664b64fa74e97c411d79b
Public record ID
record:sha256:61671c9aac485bf157d4e9a44b7e150b0228b6a68fd945528f2dea7933124d3b

This is source-provided metadata, not an enriched summary or an impact assessment. Follow the canonical source link for the published material.

Evidence and limitations

Source ID
aws_security_bulletins
Record identifier
61671c9aac485bf157d4e9a44b7e150b0228b6a68fd945528f2dea7933124d3b
Record type
Source metadata

This record may overlap with other records. Source metadata can be incomplete or change. Validate consequential decisions against the linked source and your own environment.

Record · CVE-2026-18394 - Incorrect authorization in Strands Agents Tools http_request tool · Baitaphish