CVE-2026-90819
A weakness has been identified in a2aproject a2a-java 1.2.0. The affected element is the function BasePushNotificationSender.dispatchNotification of the file server-common/src/main/java/org/a2aproject/sdk/server/tasks/BasePushNotificationSender.java of the component Authorization Header Construction. This manipulation causes http response splitting. The attack can be initiated remotely. Upgrading to version 1.3.0 is sufficient to fix this issue. Patch name: 247a655043f145f6f8e3853724b6a543eaa02001. You should upgrade the affected component.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 7.5
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X
- EPSS probability
- 0.39%
- CWE
- CWE-113, CWE-93
- Published
- 2026-09-14
- Last modified
- 2026-09-15
Affected products
- a2aproject a2a-java
- a2aproject a2a-java
Weakness type
Related vulnerabilities
- CVE-2026-34520 — AIOHTTP: C parser (llhttp) accepts null bytes and control characters in response header values - header injection / security bypass
- CVE-2025-53007 — arduino-esp32 vulnerable to CRLF injection in WebServer.cpp
- CVE-2021-0268 — Junos OS: J-Web has an Improper Neutralization of CRLF Sequences in its HTTP Headers which allows an attacker to carry out multiple types of attacks.
- CVE-2024-52875 — An issue was discovered in GFI Kerio Control 9.2.5 through 9.4.5. The dest GET parameter passed to the /nonauth/addCertE
- CVE-2025-61689 — HTTP.jl vulnerable to Header injection/Response splitting via header construction.
- CVE-2025-53094 — ESPAsyncWebServer Vulnerable to CRLF Injection in AsyncWebHeader.cpp
- CVE-2025-59151 — Pi-hole Admin Interface vulnerable to HTTP response header injection via CRLF injection
- CVE-2026-67289 — FreeRDP before 3.29.0 HTTP Proxy Request Injection via Redirection