Impact
The flaw arises during the construction of the Authorization header in the BasePushNotificationSender.dispatchNotification method. Unsanitized user input can inject CRLF sequences, resulting in HTTP response splitting. This vulnerability is classified under CWE-113 (HTTP Response Splitting) and CWE-93 (Improper Interpretation of CRLF). Attackers can leverage the split to inject arbitrary headers or alter the response body.
Affected Systems
The issue affects the a2aproject a2a- java component. Specifically, all releases prior to 1.3.0, including the 1.2.0 release at which the weakness was documented, are vulnerable. The problem resides in the BasePushNotificationSender class within the server-common module. Updating to version 1.3.0 or later resolves the issue.
Risk and Exploitability
The vulnerability carries a CVSS score of 6.9, indicating a moderate impact. No EPSS score is available, and it is not currently listed in the CISA KEV catalog. The attack can be initiated remotely by sending a crafted HTTP request with a malicious Authorization header containing CRLF characters. Because the code does not validate or sanitize this header, the exploited response splitting can be achieved with minimal effort, providing a convenient vector for attackers without requiring privileged access.
OpenCVE Enrichment