CVE-2026-54735

Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in Prebid Server interpolate user-supplied parameters into outbound request URLs without properly validating host and subdomain values, allowing crafted bid request parameters to cause server-side requests to unintended destinations and potentially expose internal network services or sensitive server endpoints. This issue is fixed in version 4.4.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:prebid:prebid_server:*:*:*:*:*:go:*:*

History

No history.

Information

Published : 2026-07-29 16:17

Updated : 2026-08-18 14:09


NVD link : CVE-2026-54735

Mitre link : CVE-2026-54735

CVE.ORG link : CVE-2026-54735


JSON object : View

Products Affected

prebid

  • prebid_server
CWE
CWE-918

Server-Side Request Forgery (SSRF)