CPE
CVE-2026-90819 identifies an HTTP response splitting vulnerability in the Authorization Header Construction component of a2a-java 1.2.0, enabling remote attackers to manipulate HTTP responses.