PT-2026-65831 · Unknown · Prebid-Server
CVE-2026-54735
·
Published
2026-07-29
·
Updated
2026-07-29
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Prebid Server versions prior to 4.4.0
Description
Certain bidder adapters interpolate user-supplied parameters into outbound request URLs without proper validation of host and subdomain values. This allows a malicious actor to craft bid request parameters that force the server to send HTTP requests to unintended destinations, which could expose internal network services or sensitive server endpoints to unauthorized access.
Recommendations
Update to version 4.4.0.
Disable the affected bidder adapters as a temporary workaround.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Prebid-Server