Server-Side Request Forgery in a2aproject a2a-python Push Notification Sender
CVE-2026-90790
5.3MEDIUM
What is CVE-2026-90790?
A significant vulnerability has been identified in the a2aproject a2a-python software, specifically within the Push Notification Sender component. The issue arises in the _dispatch_notification function where improper handling of the push_info.url parameter can lead to server-side request forgery (SSRF). This issue allows an attacker to manipulate requests sent by the server, potentially exposing sensitive information or causing further system compromise. It is crucial for users to upgrade to version 1.1.4 or later to effectively address this security risk.
Affected Version(s)
a2a-python 1.1.0
a2a-python 1.1.1
a2a-python 1.1.2
