Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-90820— a2aproject a2a-java AuthorizationRequestHandlerDecorator.java AuthorizationRequestHandlerDecorator.onListTasks authorization

Quick assessment

Affected
a2aproject a2a-java
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 a2aproject a2a-java 1.2.0 中检测到一处安全漏洞。受影响的组件是文件 中的 函数。该问题会导致授权缺失(missing authorization),且攻击者可远程发起攻击。升级到 1.3.0 版本即可解决此问题。对应的补丁编号为 。建议将受影响的组件升级至该版本。

CVSS 4.3 · Medium
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-90820

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
a2aproject a2a-java AuthorizationRequestHandlerDecorator.java AuthorizationRequestHandlerDecorator.onListTasks authorization
Source: CVE Program / CVE List V5
Vulnerability Description
A security vulnerability has been detected in a2aproject a2a-java 1.2.0. The impacted element is the function AuthorizationRequestHandlerDecorator.onListTasks of the file server-common/src/main/java/org/a2aproject/sdk/server/requesthandlers/AuthorizationRequestHandlerDecorator.java. Such manipulation leads to missing authorization. The attack can be launched remotely. Upgrading to version 1.3.0 is sufficient to resolve this issue. The name of the patch is e9a1abf9c90c02b16d17293afdc3cc2f555d63a6. The affected component should be upgraded.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
a2aproject a2a-java 1.2.0 cpe:2.3:a:a2aproject:a2a-java:*:*:*:*:*:*:*:*

II. Public POCs for CVE-2026-90820

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-90820

登录查看更多情报信息。

Patches & Fixes for CVE-2026-90820 (2)

Vendor Pages for CVE-2026-90820 (2)

Same Patch Batch · a2aproject · 2026-09-14 · 3 CVEs total

CVE-2026-90819 7.3 HIGH a2aproject a2a-java Authorization Header Construction BasePushNotificationSender.java Base
CVE-2026-90790 6.3 MEDIUM a2aproject a2a-python Push Notification Sender base_push_notification_sender.py _dispatch_

IV. Related Vulnerabilities

V. Comments for CVE-2026-90820

No comments yet


Leave a comment