Description
A security vulnerability has been detected in a2aproject a2a-python up to 1.1.3. This affects the function _dispatch_notification of the file src/a2a/server/tasks/base_push_notification_sender.py of the component Push Notification Sender. The manipulation of the argument push_info.url leads to server-side request forgery. Remote exploitation of the attack is possible. Upgrading to version 1.1.4 is able to mitigate this issue. It is suggested to upgrade the affected component.
Published: 2026-09-14
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Server‑Side Request Forgery enabling outbound request execution
Action: Immediate Patch
AI Analysis

Impact

A security weakness exists in the _dispatch_notification function of a2a‑python’s Push Notification Sender; the push_info.url argument can be controlled by an attacker, causing the application to issue arbitrary HTTP requests. This server‑side request forgery (CWE‑918) allows a remote attacker to trigger outbound traffic to any destination reachable from the host, creating opportunities to exfiltrate data, access internal services, or perform denial‑of‑service attacks against back‑end systems.

Affected Systems

All installations of the a2aproject a2a‑python component running version 1.1.3 or earlier are affected. The flaw is remedied in release 1.1.4, which implements input validation to restrict the destination URL.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and no EPSS data is currently available. The vulnerability is not listed in the CISA KEV catalog. Attackers can trigger it remotely without authentication and can manipulate outbound connections, making it a useful vector for further internal exploitation given the application's network reach.

Generated by OpenCVE AI on September 15, 2026 at 13:59 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the a2a‑python component to version 1.1.4 or later, which validates and limits the push_info.url field.
  • If a patch cannot be applied immediately, enforce outbound destination restrictions at the network layer or configure the Push Notification Sender to use a whitelist of allowed URLs to block arbitrary request targets.
  • Disable or isolate the Push Notification Sender service until a patched version is available and monitor outbound traffic for unexpected requests originating from the application.

Generated by OpenCVE AI on September 15, 2026 at 13:59 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A security vulnerability has been detected in a2aproject a2a-python up to 1.1.3. This affects the function _dispatch_notification of the file src/a2a/server/tasks/base_push_notification_sender.py of the component Push Notification Sender. The manipulation of the argument push_info.url leads to server-side request forgery. Remote exploitation of the attack is possible. Upgrading to version 1.1.4 is able to mitigate this issue. It is suggested to upgrade the affected component.
Title a2aproject a2a-python Push Notification Sender base_push_notification_sender.py _dispatch_notification server-side request forgery
First Time appeared A2aproject
A2aproject a2a-python
Weaknesses CWE-918
CPEs cpe:2.3:a:a2aproject:a2a-python:*:*:*:*:*:*:*:*
Vendors & Products A2aproject
A2aproject a2a-python
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

A2aproject A2a-python
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T13:56:53.326Z

Reserved: 2026-09-13T13:24:51.272Z

Link: CVE-2026-90790

cve-icon Vulnrichment

Updated: 2026-09-15T13:33:23.059Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T15:17:13.200

Modified: 2026-09-15T14:17:35.557

Link: CVE-2026-90790

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T14:00:11Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)