CVE-2026-90819
a2aproject a2a-java Authorization Header Construction BasePushNotificationSender.java BasePushNotificationSender.dispatchNotification response splitting
CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th
A weakness has been identified in a2aproject a2a-java 1.2.0. The affected element is the function BasePushNotificationSender.dispatchNotification of the file server-common/src/main/java/org/a2aproject/sdk/server/tasks/BasePushNotificationSender.java of the component Authorization Header Construction. This manipulation causes http response splitting. The attack can be initiated remotely. Upgrading to version 1.3.0 is sufficient to fix this issue. Patch name: 247a655043f145f6f8e3853724b6a543eaa02001. You should upgrade the affected component.
| CWE | CWE-113 CWE-93 |
| Vendor | a2aproject |
| Product | a2a-java |
| Published | Sep 14, 2026 |
| Last Updated | Sep 15, 2026 |
Stay Ahead of the Next One
Get instant alerts for a2aproject a2a-java
Be the first to know when new high vulnerabilities affecting a2aproject a2a-java are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability
Affected Versions
a2aproject / a2a-java
1.2.0
References
vuldb.com: https://vuldb.com/vuln/403322 vuldb.com: https://vuldb.com/vuln/403322/cti vuldb.com: https://vuldb.com/cve/CVE-2026-90819 vuldb.com: https://vuldb.com/submit/922996 github.com: https://github.com/a2aproject/a2a-java/pull/1043 github.com: https://github.com/a2aproject/a2a-java/pull/1053 github.com: https://github.com/a2aproject/a2a-java/commit/247a655043f145f6f8e3853724b6a543eaa02001 github.com: https://github.com/a2aproject/a2a-java/releases/tag/v1.3.0.Final github.com: https://github.com/a2aproject/a2a-java/
Credits
๐ ez-lbz (VulDB User)