Description
A weakness has been identified in a2aproject a2a-java 1.2.0. The affected element is the function BasePushNotificationSender.dispatchNotification of the file server-common/src/main/java/org/a2aproject/sdk/server/tasks/BasePushNotificationSender.java of the component Authorization Header Construction. This manipulation causes http response splitting. The attack can be initiated remotely. Upgrading to version 1.3.0 is sufficient to fix this issue. Patch name: 247a655043f145f6f8e3853724b6a543eaa02001. You should upgrade the affected component.
Published: 2026-09-14
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: HTTP Response Splitting
Action: Upgrade Component
AI Analysis

Impact

The flaw arises during the construction of the Authorization header in the BasePushNotificationSender.dispatchNotification method. Unsanitized user input can inject CRLF sequences, resulting in HTTP response splitting. This vulnerability is classified under CWE-113 (HTTP Response Splitting) and CWE-93 (Improper Interpretation of CRLF). Attackers can leverage the split to inject arbitrary headers or alter the response body.

Affected Systems

The issue affects the a2aproject a2a- java component. Specifically, all releases prior to 1.3.0, including the 1.2.0 release at which the weakness was documented, are vulnerable. The problem resides in the BasePushNotificationSender class within the server-common module. Updating to version 1.3.0 or later resolves the issue.

Risk and Exploitability

The vulnerability carries a CVSS score of 6.9, indicating a moderate impact. No EPSS score is available, and it is not currently listed in the CISA KEV catalog. The attack can be initiated remotely by sending a crafted HTTP request with a malicious Authorization header containing CRLF characters. Because the code does not validate or sanitize this header, the exploited response splitting can be achieved with minimal effort, providing a convenient vector for attackers without requiring privileged access.

Generated by OpenCVE AI on September 15, 2026 at 11:54 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the a2a-java component to version 1.3.0 or newer, which contains the authorization header sanitization fix.
  • If upgrading is not immediately possible, configure application or network firewalls to reject or strip CRLF characters from incoming Authorization headers.
  • Audit and validate that all code paths constructing Authorization headers perform strict input checks to eliminate CRLF injection.

Generated by OpenCVE AI on September 15, 2026 at 11:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 15 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in a2aproject a2a-java 1.2.0. The affected element is the function BasePushNotificationSender.dispatchNotification of the file server-common/src/main/java/org/a2aproject/sdk/server/tasks/BasePushNotificationSender.java of the component Authorization Header Construction. This manipulation causes http response splitting. The attack can be initiated remotely. Upgrading to version 1.3.0 is sufficient to fix this issue. Patch name: 247a655043f145f6f8e3853724b6a543eaa02001. You should upgrade the affected component.
Title a2aproject a2a-java Authorization Header Construction BasePushNotificationSender.java BasePushNotificationSender.dispatchNotification response splitting
First Time appeared A2aproject
A2aproject a2a-java
Weaknesses CWE-113
CWE-93
CPEs cpe:2.3:a:a2aproject:a2a-java:*:*:*:*:*:*:*:*
Vendors & Products A2aproject
A2aproject a2a-java
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:OF/RC:C'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

A2aproject A2a-java
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-09-15T14:25:39.139Z

Reserved: 2026-09-13T19:01:37.271Z

Link: CVE-2026-90819

cve-icon Vulnrichment

Updated: 2026-09-15T14:25:35.516Z

cve-icon NVD

Status : Deferred

Published: 2026-09-14T21:17:42.177

Modified: 2026-09-15T15:17:30.050

Link: CVE-2026-90819

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T12:00:16Z

Weaknesses
  • CWE-113

    Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting')

  • CWE-93

    Improper Neutralization of CRLF Sequences ('CRLF Injection')