๐Ÿ” CVE Alert

CVE-2026-90819

HIGH 7.3

a2aproject a2a-java Authorization Header Construction BasePushNotificationSender.java BasePushNotificationSender.dispatchNotification response splitting

CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th

A weakness has been identified in a2aproject a2a-java 1.2.0. The affected element is the function BasePushNotificationSender.dispatchNotification of the file server-common/src/main/java/org/a2aproject/sdk/server/tasks/BasePushNotificationSender.java of the component Authorization Header Construction. This manipulation causes http response splitting. The attack can be initiated remotely. Upgrading to version 1.3.0 is sufficient to fix this issue. Patch name: 247a655043f145f6f8e3853724b6a543eaa02001. You should upgrade the affected component.

CWE CWE-113 CWE-93
Vendor a2aproject
Product a2a-java
Published Sep 14, 2026
Last Updated Sep 15, 2026
Stay Ahead of the Next One

Get instant alerts for a2aproject a2a-java

Be the first to know when new high vulnerabilities affecting a2aproject a2a-java are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

a2aproject / a2a-java
1.2.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/403322 vuldb.com: https://vuldb.com/vuln/403322/cti vuldb.com: https://vuldb.com/cve/CVE-2026-90819 vuldb.com: https://vuldb.com/submit/922996 github.com: https://github.com/a2aproject/a2a-java/pull/1043 github.com: https://github.com/a2aproject/a2a-java/pull/1053 github.com: https://github.com/a2aproject/a2a-java/commit/247a655043f145f6f8e3853724b6a543eaa02001 github.com: https://github.com/a2aproject/a2a-java/releases/tag/v1.3.0.Final github.com: https://github.com/a2aproject/a2a-java/

Credits

๐Ÿ” ez-lbz (VulDB User)