CVE-2026-54734
Prebid Server Java: Vulnerability to request forgery allows for possible host environment data extraction
CVSS Score
10.0
EPSS Score
0.0%
EPSS Percentile
0th
Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate the resulting domain or path segment. A malicious actor who can supply bid-request parameters can cause the server to send HTTP requests to unintended destinations, potentially reaching internal network services, metadata endpoints, or other sensitive server endpoints with the server's network access. This issue is fixed in version 3.43.0.
| CWE | CWE-918 |
| Vendor | prebid |
| Product | prebid-server-java |
| Published | Sep 17, 2026 |
Stay Ahead of the Next One
Get instant alerts for prebid prebid-server-java
Be the first to know when new critical vulnerabilities affecting prebid prebid-server-java are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Changed
Confidentiality
High
Integrity
High
Availability
High
Affected Versions
prebid / prebid-server-java
< 3.43.0
References
github.com: https://github.com/prebid/prebid-server-java/security/advisories/GHSA-fr2c-g2f8-qchg github.com: https://github.com/prebid/prebid-server-java/pull/4522 github.com: https://github.com/prebid/prebid-server-java/commit/a129a685b6fc54441c1a779ce29ea4ec20c2e09f github.com: https://github.com/prebid/prebid-server-java/commit/d0c723ce36aa09712c825ea9625d978f45d29a1c github.com: https://github.com/prebid/prebid-server-java/releases/tag/3.43.0