{"id":"CVE-2026-90790","title":"A security vulnerability has been detected in a2aproject a2a-python up to 1.1.3","summary":"A security vulnerability has been detected in a2aproject a2a-python up to 1.1.3. This affects the function _dispatch_notification of the file src/a2a/server/tasks/base_push_notification_sender.py of the component Push Notification Sender…","severity":"medium","cvss":6.3,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L","cwe":["CWE-918"],"vendor":"a2aproject","product":"a2a-python","affected":["a2a-python 1.1.0","a2a-python 1.1.1","a2a-python 1.1.2","a2a-python 1.1.3"],"published":"2026-09-14","updated":"2026-09-15","sourceUpdated":"2026-09-15T14:17:35.557","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-90790","references":[{"url":"https://github.com/a2aproject/a2a-python/","label":"cna@vuldb.com"},{"url":"https://github.com/a2aproject/a2a-python/pull/1164","label":"cna@vuldb.com"},{"url":"https://github.com/a2aproject/a2a-python/pull/1169","label":"cna@vuldb.com"},{"url":"https://github.com/a2aproject/a2a-python/releases/tag/v1.1.4","label":"cna@vuldb.com"},{"url":"https://vuldb.com/cve/CVE-2026-90790","label":"cna@vuldb.com"},{"url":"https://vuldb.com/submit/919747","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/403296","label":"cna@vuldb.com"},{"url":"https://vuldb.com/vuln/403296/cti","label":"cna@vuldb.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-15T13:33:15.907930Z"},"epss":0.00214,"epssPercentile":0.12086,"ingestedAt":"2026-09-14T15:23:07.424Z","slug":"CVE-2026-90790","body":"## Overview\n\nA security vulnerability has been detected in a2aproject a2a-python up to 1.1.3. This affects the function _dispatch_notification of the file src/a2a/server/tasks/base_push_notification_sender.py of the component Push Notification Sender. The manipulation of the argument push_info.url leads to server-side request forgery. Remote exploitation of the attack is possible. Upgrading to version 1.1.4 is able to mitigate this issue. It is suggested to upgrade the affected component.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":35,"depthScoreParts":{"impact":34.7,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}