Advisory Database
  • Advisories
  • Dependency Scanning
  1. golang
  2. ›
  3. github.com/prebid/prebid-server/v3
  4. ›
  5. CVE-2026-54735

CVE-2026-54735: prebid-server's request forgery vulnerability allows for possible host environment data extraction

July 29, 2026

Certain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints to unauthorized access.

References

  • github.com/advisories/GHSA-4p3g-4hcj-wpvx
  • github.com/prebid/prebid-server/commit/494ac271cd4b5024df9123ef25ca3cff96390be3
  • github.com/prebid/prebid-server/pull/4802
  • github.com/prebid/prebid-server/releases/tag/v4.4.0
  • github.com/prebid/prebid-server/security/advisories/GHSA-4p3g-4hcj-wpvx
  • nvd.nist.gov/vuln/detail/CVE-2026-54735

Code Behaviors & Features

Detect and mitigate CVE-2026-54735 with GitLab Dependency Scanning

Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →

Affected versions

All versions up to 3.30.0

Solution

Unfortunately, there is no solution available yet.

Impact 10 CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Learn more about CVSS

Weakness

  • CWE-918: Server-Side Request Forgery (SSRF)

Source file

go/github.com/prebid/prebid-server/v3/CVE-2026-54735.yml

Spotted a mistake? Edit the file on GitLab.

  • Site Repo
  • About GitLab
  • Terms
  • Privacy Statement
  • Contact

Page generated Sat, 08 Aug 2026 00:18:44 +0000.