Feed/CVE-2026-54735
CVE-2026-54735CRITICALCVSS 10.0

prebid-server's request forgery vulnerability allows for possible host environment data extraction

Published Jul 29, 2026·Updated Aug 18, 2026

NVD Description

### Impact Certain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints to unauthorized access. ### Patches Patched in [v4.4.0](https://github.com/prebid/prebid-server/releases/tag/v4.4.0) ### Workarounds If one is unable to update, please make sure that the affected bidder adapters are disabled.

Affected Packages (4)

github.com/prebid/prebid-serverGO
Fixed in = 0.275.0
github.com/prebid/prebid-server/v2GO
Fixed in = 2.32.0
github.com/prebid/prebid-server/v4GO
Fixed in 4.4.0
github.com/prebid/prebid-server/v3GO
Fixed in = 3.30.0

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free