a2aproject / a2aproject/A2A

Security disclosure: awaiting response on two reported vulnerabilities

Offen
#2,024 2 Kommentare 0 Reaktionen 0 zugewiesene Personen Auf GitHub ansehen
Vorherrschende Sprache
Shell
Sterne
25.8k
Forks
2.6k
Ø Merge
3 T. 6 Std.
Gemergte PRs (30 T.)
16

Beschreibung

Hi A2A maintainers,

We're a security research team that identified two design-level security
issues in the A2A protocol specification (v1.0.0). We reported these privately
to security@lists.a2aproject.org on two occasions, first on **June 8, 2026** and
again on **June 22, 2026**.

We haven't received a response or acknowledgment to either email, so we're
opening this issue to reach the team directly and confirm the right channel.
We're deliberately not including technical details here, to avoid publicly
disclosing unpatched issues.

Could you let us know the best way to proceed? Specifically:

- Is security@lists.a2aproject.org the correct and monitored security contact,
or is there another process we should be using?
- Is there a specific maintainer or governance contact we should route this to
directly?

We'd prefer to keep coordinating privately and give the team appropriate time
to review before anything becomes public.

For context on timing: the work describing these issues is under review at a
major security conference, so it may enter the public record in the coming
weeks as part of that process. We wanted to make sure the maintainers have a
chance to assess and respond before then.

Happy to share full details as soon as we have a confirmed secure channel.
Thanks.

Beitragsleitfaden

Beitragsleitfaden öffnen

Rechercherichtung

Dies ist eine Sicherheitsmeldung, die auf eine Kontaktaufnahme durch die Maintainer wartet. Das Issue beschreibt die Schwachstellen nicht. Ein Neuling müsste warten, bis die Maintainer einen sicheren Kanal eingerichtet haben, und dann die privaten Details prüfen. Die Forschungsrichtung besteht darin, das Issue auf eine Antwort des Sicherheitsteams oder der Maintainer zu überwachen.

Vom Indexierungsmodell aus dem Issue-Text verfasst.

Bewertung

Bereich
security
Issue-Typ
Bug
Schwierigkeit
5/5
Geschätzter Aufwand
Über eine Woche
Aktivitätsstatus
Ruhig
Klarheit
Größtenteils klar
Anfängerfreundlichkeit
20/100

Neue Issues direkt in Ihr Postfach

Eine kurze Übersicht über anfängerfreundliche GitHub-Issues.