CVE-2026-54735: prebid-server's request forgery vulnerability allows for possible host environment data extraction
Certain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints to unauthorized access.
References
- github.com/advisories/GHSA-4p3g-4hcj-wpvx
- github.com/prebid/prebid-server/commit/494ac271cd4b5024df9123ef25ca3cff96390be3
- github.com/prebid/prebid-server/pull/4802
- github.com/prebid/prebid-server/releases/tag/v4.4.0
- github.com/prebid/prebid-server/security/advisories/GHSA-4p3g-4hcj-wpvx
- nvd.nist.gov/vuln/detail/CVE-2026-54735
Code Behaviors & Features
Detect and mitigate CVE-2026-54735 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →