Server-Side Request Forgery in a2aproject a2a-python Push Notification Sender
CVE-2026-90790

5.3MEDIUM

Key Information:

Vendor

A2aproject

Vendor
CVE Published:
14 September 2026

What is CVE-2026-90790?

A significant vulnerability has been identified in the a2aproject a2a-python software, specifically within the Push Notification Sender component. The issue arises in the _dispatch_notification function where improper handling of the push_info.url parameter can lead to server-side request forgery (SSRF). This issue allows an attacker to manipulate requests sent by the server, potentially exposing sensitive information or causing further system compromise. It is crucial for users to upgrade to version 1.1.4 or later to effectively address this security risk.

Affected Version(s)

a2a-python 1.1.0

a2a-python 1.1.1

a2a-python 1.1.2

References

CVSS V4

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ez-lbz (VulDB User)
.