a2aproject has 3 CVEs on record. 3 were published in the last 90 days. The busiest recent month was September 2026 with 3. The median CVSS is 6.3 (medium). Most affected products: a2a-java (2), a2a-python (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 6.3
- Publish → KEV
- —
- Last 90 days
- 3 prev 0
Worst active — by depth score
a2aproject vulnerabilities
CVEs affecting a2aproject, newest first. Open any entry for full detail, references, and exploit status.
3 CVEsRSS
CVE-2026-90819High· 7.3A weakness has been identified in a2aproject a2a-java 1.2.0
A weakness has been identified in a2aproject a2a-java 1.2.0. The affected element is the function BasePushNotificationSender.dispatchNotification of the file server-common/src/main/java/org/a2aproject/sdk/server/tasks/BasePushNotificatio…
CVE-2026-90820Medium· 4.3A security vulnerability has been detected in a2aproject a2a-java 1.2.0
A security vulnerability has been detected in a2aproject a2a-java 1.2.0. The impacted element is the function AuthorizationRequestHandlerDecorator.onListTasks of the file server-common/src/main/java/org/a2aproject/sdk/server/requesthandl…
CVE-2026-90790Medium· 6.3A security vulnerability has been detected in a2aproject a2a-python up to 1.1.3
A security vulnerability has been detected in a2aproject a2a-python up to 1.1.3. This affects the function _dispatch_notification of the file src/a2a/server/tasks/base_push_notification_sender.py of the component Push Notification Sender…