Executive brief
The a2a-java SDK is a library used to implement the Agent2Agent protocol for secure agent communication. A vulnerability in the push notification header construction allows attackers to inject carriage return and line feed characters, enabling HTTP response splitting attacks that could be exploited to inject malicious content into responses, manipulate headers, or compromise application behavior.
Technical details
The vulnerability is an HTTP response splitting issue (CWE-113) in the BasePushNotificationSender.dispatchNotification method of the server-common component. The root cause is insufficient validation of the Authorization header and X-A2A-Notification-Token values before they are included in HTTP responses, allowing attackers to inject CR/LF characters. The attack requires network reachability to a system using the vulnerable library and can be initiated without authentication. An attacker can exploit this to split HTTP responses, potentially injecting headers or content. The fix is available in version 1.3.0 and patch 247a655043f145f6f8e3853724b6a543eaa02001, which validates these header values before dispatch.
Affected products
- a2aproject a2a-java 1.2.0
Timeline
- 2026-09-14: disclosed
- 2026-08-11: patched: Patch 247a655043f145f6f8e3853724b6a543eaa02001 released; version 1.3.0 contains fix