A security vulnerability has been detected in a2aproject a2a-python up to 1.1.3. This affects the function _dispatch_notification of the file src/a2a/server/tasks/base_push_notification_sender.py of the component Push Notification Sender. The manipulation of the argument push_info.url leads to server-side request forgery. Remote exploitation of the attack is possible. Upgrading to version 1.1.4 is able to mitigate this issue. It is suggested to upgrade the affected component.
{
"cna_assigner": "VulDB",
"cwe_ids": [
"CWE-918"
],
"osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/90xxx/CVE-2026-90790.json"
}{
"extracted_events": [
{
"introduced": "1.1.0"
},
{
"last_affected": "1.1.0"
},
{
"introduced": "1.1.1"
},
{
"last_affected": "1.1.1"
},
{
"introduced": "1.1.2"
},
{
"last_affected": "1.1.2"
},
{
"introduced": "1.1.3"
},
{
"last_affected": "1.1.3"
}
],
"source": [
"AFFECTED_FIELD",
"REFERENCES"
]
}