CVE-2026-90790 | a2aproject a2a-python up to 1.1.3 Push Notification Sender base_push_notification_sender.py _dispatch_notification push_info.url server-side request forgery (1164/1169/1173)

SecurityVulns

A vulnerability marked as critical has been reported in a2aproject a2a-python up to 1.1.3. This affects the function _dispatch_notification of the file src/a2a/server/tasks/base_push_notification_sender.py of the component Push Notification Sender. The manipulation of the argument push_info.url leads to server-side request forgery.

This vulnerability is referenced as CVE-2026-90790. Remote exploitation of the attack is possible. No exploit is available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More