PT-2026-91249 · Pypi · Python-A2A

·

CVE-2026-90790

·

Published

2026-09-14

·

Updated

2026-09-15

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions a2aproject a2a-python versions prior to 1.1.4
Description A server-side request forgery issue exists in the Push Notification Sender component. The problem occurs within the dispatch notification() function located in the src/a2a/server/tasks/base push notification sender.py file. Remote exploitation is possible by manipulating the push info.url variable.
Recommendations Update a2aproject a2a-python to version 1.1.4.

Exploit

Fix

SSRF

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90790

Affected Products

Python-A2A