在 a2aproject a2a-java 1.2.0 中检测到一处安全漏洞。受影响的组件是文件 中的 函数。该问题会导致授权缺失(missing authorization),且攻击者可远程发起攻击。升级到 1.3.0 版本即可解决此问题。对应的补丁编号为 。建议将受影响的组件升级至该版本。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| a2aproject | a2a-java | 1.2.0 |
cpe:2.3:a:a2aproject:a2a-java:*:*:*:*:*:*:*:*
|
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-90819 | 7.3 HIGH | a2aproject a2a-java Authorization Header Construction BasePushNotificationSender.java Base |
| CVE-2026-90790 | 6.3 MEDIUM | a2aproject a2a-python Push Notification Sender base_push_notification_sender.py _dispatch_ |
No comments yet