


Perceptive Security
SOC/SIEM Consultancy

Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in Prebid Serv…
Published:
28 July 2026 at 22:00:00
Alert date:
29 July 2026 at 17:02:28
Source:
nvd.nist.gov
Web Technologies, Cloud & Virtualization
CVE-2026-54735 affects Prebid Server, an open-source real-time advertising auction platform. Prior to version 4.4.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without properly validating host and subdomain values. This flaw allows attackers to craft malicious bid request parameters that trigger server-side requests to unintended destinations, a classic Server-Side Request Forgery (SSRF) vulnerability. Exploitation could expose internal network services or sensitive server endpoints. The vulnerability has been patched in Prebid Server version 4.4.0. A corresponding GitHub security advisory (GHSA-4p3g-4hcj-wpvx) and pull request (#4802) have been published. Users are strongly advised to upgrade to v4.4.0 or later to mitigate this risk.
Technical details
Mitigation steps:
Affected products:
Prebid Server
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-54735
https://github.com/prebid/prebid-server/commit/494ac271cd4b5024df9123ef25ca3cff96390be3
https://github.com/prebid/prebid-server/pull/4802
https://github.com/prebid/prebid-server/releases/tag/v4.4.0
https://github.com/prebid/prebid-server/security/advisories/GHSA-4p3g-4hcj-wpvx
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
