Hacktoberfest 2026:メンテナが10月に向けて印を付けた、オープンで初心者向けの issue。 Hacktoberfest の issue を見る

[Bug]: Agent card signature verification raises raw binascii.Error on a malformed protected header instead of SignatureVerificationError

オープン
#1,332 コメント 0 件 リアクション 0 件 担当者 2 名 GitHub で見る

メンテナーはふだん 2 日以内に返信

@rohityan がすでに取り組んでいます。

2026年10月9日 から。

評価

この issue はまだ評価されていません。

説明

What happened?

create_signature_verifier's verification loop (src/a2a/utils/signing.py:139-159) only catches PyJWTError:

for agent_card_signature in agent_card.signatures:
    try:
        protected_header_json = base64url_decode(
            agent_card_signature.protected.encode('utf-8')
        ).decode('utf-8')                      # may raise binascii.Error / UnicodeDecodeError
        protected_header = json.loads(protected_header_json)  # may raise JSONDecodeError
        ...
        verification_key = key_provider(kid, jku)  # may raise anything (e.g. network errors)
        jwt.decode(...)
        break
    except PyJWTError:
        continue

agent_card_signature.protected is an attacker-controlled field. A malformed value makes base64url_decode raise a raw binascii.Error, which escapes the verifier entirely — violating the module's own contract: the canonicalization step just above explicitly converts failures to InvalidSignaturesError "so every failure on this path is a SignatureVerificationError", but the per-signature loop does not.

It also breaks the documented multi-signature semantic ("succeeds if at least one signature is valid"): a card holding [malformed_signature, valid_signature] raises instead of verifying.

Additionally, any exception raised by key_provider (e.g. a network failure while fetching the JKU) aborts the whole loop for the same reason.

Reproduction
from a2a.types.a2a_pb2 import AgentCard, AgentCardSignature
from a2a.utils.signing import (
    SignatureVerificationError,
    create_signature_verifier,
)

verifier = create_signature_verifier(
    key_provider=lambda kid, jku: b'dummy-key',
    algorithms=['RS256'],
)
card = AgentCard(
    name='t',
    version='1.0',
    signatures=[
        AgentCardSignature(protected='!!!not-base64url!!!', signature='aaa')
    ],
)
try:
    verifier(card)
except SignatureVerificationError as e:
    print(f'contract respected: {type(e).__name__}: {e}')
except Exception as e:
    print(f'CONTRACT BROKEN -> {type(e).__name__}: {e}')

Observed output:

CONTRACT BROKEN -> Error: Invalid base64-encoded string: number of data characters (13) cannot be 1 more than a multiple of 4
Expected behavior

Every failure on the verification path should surface as SignatureVerificationError (per the contract established at signing.py:124-128), and a malformed signature should count as "invalid" so remaining signatures are still attempted.

Suggested fix

Widen the per-signature except clause, e.g.:

except (PyJWTError, ValueError, binascii.Error, UnicodeDecodeError):
    continue

or wrap the loop body so parse/key-provider failures are logged and treated as an invalid signature. This is non-breaking for correct inputs and only converts escapes into the documented error type.

Happy to submit a PR with tests.

Code of Conduct
  • I agree to follow this project's Code of Conduct
主要言語
Python
スター
2.2k
フォーク
509
平均マージ
3日 11時間
マージ済み PR(30日)
43

環境構築

はじめの一歩

  1. issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
  2. 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
  3. リポジトリをフォークし、ブランチを切って変更します。
  4. issue 番号を参照したプルリクエストを送ります。

a2aproject/a2a-python のほかの issue

a2aproject/a2a-python の issue をすべて見る

似ている issue

Python の issue をもっと見る

新しい issue をメールで受け取る

初心者向けの GitHub issue を短くまとめたダイジェスト。