CVE-2026-54735

Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in Prebid Server interpolate user-supplied parameters into outbound request URLs without properly validating host and subdomain values, allowing crafted bid request parameters to cause server-side requests to unintended destinations and potentially expose internal network services or sensitive server endpoints. This issue is fixed in version 4.4.0.
Configurations

No configuration.

History

29 Jul 2026, 16:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-07-29 16:17

Updated : 2026-07-30 20:06


NVD link : CVE-2026-54735

Mitre link : CVE-2026-54735

CVE.ORG link : CVE-2026-54735


JSON object : View

Products Affected

No product.

CWE
CWE-918

Server-Side Request Forgery (SSRF)