๐Ÿ” CVE Alert

CVE-2026-54734

CRITICAL 10.0

Prebid Server Java: Vulnerability to request forgery allows for possible host environment data extraction

CVSS Score
10.0
EPSS Score
0.0%
EPSS Percentile
0th

Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate the resulting domain or path segment. A malicious actor who can supply bid-request parameters can cause the server to send HTTP requests to unintended destinations, potentially reaching internal network services, metadata endpoints, or other sensitive server endpoints with the server's network access. This issue is fixed in version 3.43.0.

CWE CWE-918
Vendor prebid
Product prebid-server-java
Published Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for prebid prebid-server-java

Be the first to know when new critical vulnerabilities affecting prebid prebid-server-java are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High

Affected Versions

prebid / prebid-server-java
< 3.43.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/prebid/prebid-server-java/security/advisories/GHSA-fr2c-g2f8-qchg github.com: https://github.com/prebid/prebid-server-java/pull/4522 github.com: https://github.com/prebid/prebid-server-java/commit/a129a685b6fc54441c1a779ce29ea4ec20c2e09f github.com: https://github.com/prebid/prebid-server-java/commit/d0c723ce36aa09712c825ea9625d978f45d29a1c github.com: https://github.com/prebid/prebid-server-java/releases/tag/3.43.0