Skip to content

[Bug]: Agent card signature verification raises raw binascii.Error on a malformed protected header instead of SignatureVerificationError #1332

Description

@Linux2010

What happened?

create_signature_verifier's verification loop (src/a2a/utils/signing.py:139-159) only catches PyJWTError:

for agent_card_signature in agent_card.signatures:
    try:
        protected_header_json = base64url_decode(
            agent_card_signature.protected.encode('utf-8')
        ).decode('utf-8')                      # may raise binascii.Error / UnicodeDecodeError
        protected_header = json.loads(protected_header_json)  # may raise JSONDecodeError
        ...
        verification_key = key_provider(kid, jku)  # may raise anything (e.g. network errors)
        jwt.decode(...)
        break
    except PyJWTError:
        continue

agent_card_signature.protected is an attacker-controlled field. A malformed value makes base64url_decode raise a raw binascii.Error, which escapes the verifier entirely — violating the module's own contract: the canonicalization step just above explicitly converts failures to InvalidSignaturesError "so every failure on this path is a SignatureVerificationError", but the per-signature loop does not.

It also breaks the documented multi-signature semantic ("succeeds if at least one signature is valid"): a card holding [malformed_signature, valid_signature] raises instead of verifying.

Additionally, any exception raised by key_provider (e.g. a network failure while fetching the JKU) aborts the whole loop for the same reason.

Reproduction

from a2a.types.a2a_pb2 import AgentCard, AgentCardSignature
from a2a.utils.signing import (
    SignatureVerificationError,
    create_signature_verifier,
)

verifier = create_signature_verifier(
    key_provider=lambda kid, jku: b'dummy-key',
    algorithms=['RS256'],
)
card = AgentCard(
    name='t',
    version='1.0',
    signatures=[
        AgentCardSignature(protected='!!!not-base64url!!!', signature='aaa')
    ],
)
try:
    verifier(card)
except SignatureVerificationError as e:
    print(f'contract respected: {type(e).__name__}: {e}')
except Exception as e:
    print(f'CONTRACT BROKEN -> {type(e).__name__}: {e}')

Observed output:

CONTRACT BROKEN -> Error: Invalid base64-encoded string: number of data characters (13) cannot be 1 more than a multiple of 4

Expected behavior

Every failure on the verification path should surface as SignatureVerificationError (per the contract established at signing.py:124-128), and a malformed signature should count as "invalid" so remaining signatures are still attempted.

Suggested fix

Widen the per-signature except clause, e.g.:

except (PyJWTError, ValueError, binascii.Error, UnicodeDecodeError):
    continue

or wrap the loop body so parse/key-provider failures are logged and treated as an invalid signature. This is non-breaking for correct inputs and only converts escapes into the documented error type.

Happy to submit a PR with tests.

Code of Conduct

  • I agree to follow this project's Code of Conduct
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions