top of page
perceptive_background_267k.jpg

Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in Prebid Serv…

Published:

28 July 2026 at 22:00:00

Alert date:

29 July 2026 at 17:02:28

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Cloud & Virtualization

CVE-2026-54735 affects Prebid Server, an open-source real-time advertising auction platform. Prior to version 4.4.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without properly validating host and subdomain values. This flaw allows attackers to craft malicious bid request parameters that trigger server-side requests to unintended destinations, a classic Server-Side Request Forgery (SSRF) vulnerability. Exploitation could expose internal network services or sensitive server endpoints. The vulnerability has been patched in Prebid Server version 4.4.0. A corresponding GitHub security advisory (GHSA-4p3g-4hcj-wpvx) and pull request (#4802) have been published. Users are strongly advised to upgrade to v4.4.0 or later to mitigate this risk.

Technical details

Mitigation steps:

Affected products:

Prebid Server

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page