CVE-2026-90819 | a2aproject a2a-java 1.2.0 Authorization Header Construction BasePushNotificationSender.java BasePushNotificationSender.dispatchNotification response splitting (1043/1053)
A vulnerability identified as critical has been detected in a2aproject a2a-java 1.2.0. The affected element is the function BasePushNotificationSender.dispatchNotification of the file server-common/src/main/java/org/a2aproject/sdk/server/tasks/BasePushNotificationSender.java of the component Authorization Header Construction. This manipulation causes http response splitting.
This vulnerability is handled as CVE-2026-90819. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.VulDB Recent EntriesRead More