Security disclosure: awaiting response on two reported vulnerabilities
- Dominant language
- Shell
- Stars
- 25.7k
- Forks
- 2.6k
- Avg merge
- 3d 6h
- Merged PRs (30d)
- 16
Description
Hi A2A maintainers,
We're a security research team that identified two design-level security
issues in the A2A protocol specification (v1.0.0). We reported these privately
to security@lists.a2aproject.org on two occasions, first on **June 8, 2026** and
again on **June 22, 2026**.
We haven't received a response or acknowledgment to either email, so we're
opening this issue to reach the team directly and confirm the right channel.
We're deliberately not including technical details here, to avoid publicly
disclosing unpatched issues.
Could you let us know the best way to proceed? Specifically:
- Is security@lists.a2aproject.org the correct and monitored security contact,
or is there another process we should be using?
- Is there a specific maintainer or governance contact we should route this to
directly?
We'd prefer to keep coordinating privately and give the team appropriate time
to review before anything becomes public.
For context on timing: the work describing these issues is under review at a
major security conference, so it may enter the public record in the coming
weeks as part of that process. We wanted to make sure the maintainers have a
chance to assess and respond before then.
Happy to share full details as soon as we have a confirmed secure channel.
Thanks.
Contributor guide
Assessment
This issue has not been assessed yet.