CVE-2026-90819
Deferred Deferred - Pending Action

HTTP Response Splitting in a2a-java

Vulnerability report for CVE-2026-90819, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-14

Last updated on: 2026-09-15

Assigner: VulDB

Description

A weakness has been identified in a2aproject a2a-java 1.2.0. The affected element is the function BasePushNotificationSender.dispatchNotification of the file server-common/src/main/java/org/a2aproject/sdk/server/tasks/BasePushNotificationSender.java of the component Authorization Header Construction. This manipulation causes http response splitting. The attack can be initiated remotely. Upgrading to version 1.3.0 is sufficient to fix this issue. Patch name: 247a655043f145f6f8e3853724b6a543eaa02001. You should upgrade the affected component.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-14
Last Modified
2026-09-15
Generated
2026-10-05
AI Q&A
2026-09-15
EPSS Evaluated
2026-10-03
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
a2aproject a2a-java to 1.3.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-113 The product receives data from an HTTP agent/component (e.g., web server, proxy, browser, etc.), but it does not neutralize or incorrectly neutralizes CR and LF characters before the data is included in outgoing HTTP headers.
CWE-93 The product uses CRLF (carriage return line feeds) as a special element, e.g. to separate lines or records, but it does not neutralize or incorrectly neutralizes CRLF sequences from inputs.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an HTTP response splitting weakness in a2aproject a2a-java version 1.2.0. It occurs in the BasePushNotificationSender.dispatchNotification function due to improper handling of the Authorization header. Attackers can manipulate this to inject malicious data into HTTP responses, potentially leading to cache poisoning or session hijacking.

Detection Guidance

This vulnerability is specific to a2aproject a2a-java 1.2.0 and involves HTTP response splitting via Authorization Header Construction. Detection requires checking the installed version of a2a-java. Use commands like 'find / -name a2a-java 2>/dev/null' or 'dpkg -l | grep a2a-java' to locate the package. Verify the version with 'java -jar <path-to-jar> --version' or check Maven/Gradle dependencies in your project files.

Impact Analysis

An attacker could exploit this to split HTTP responses, redirect users to malicious sites, or inject harmful content. This may result in phishing attacks, session theft, or unauthorized access to sensitive data. The impact depends on the application's use of the affected component.

Compliance Impact

This vulnerability involves HTTP response splitting due to improper handling of the Authorization header in a2a-java 1.2.0. Such flaws can enable session hijacking or injection attacks, potentially exposing sensitive data. While not explicitly tied to GDPR or HIPAA, improper session management or data exposure risks could lead to violations of these regulations if personal or health data is compromised.

Mitigation Strategies

Upgrade the a2a-java component to version 1.3.0 or later to resolve the vulnerability. The patch is identified as 247a655043f145f6f8e3853724b6a543eaa02001.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-90819. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart