CVE-2026-54735
Critical · CVSS 10.0- CVSS
- 10.0
- nvd
- EPSS
- —
- KEV
- No
- Class
- oss containerizable
- CWE-918
Description
Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in Prebid Server interpolate user-supplied parameters into outbound request URLs without properly validating host and subdomain values, allowing crafted bid request parameters to cause server-side requests to unintended destinations and potentially expose internal network services or sensitive server endpoints. This issue is fixed in version 4.4.0.
Affected packages
| Go | github.com/prebid/prebid-server | 0 → ∞ |
| Go | github.com/prebid/prebid-server/v2 | 0 → ∞ |
| Go | github.com/prebid/prebid-server/v3 | 0 → ∞ |
| Go | github.com/prebid/prebid-server/v4 | 0 → 4.4.0 |
References
Status: profiled · ingested 2026-07-31T00:00:00.000Z