GHSA-4p3g-4hcj-wpvxCriticalCVSS 10.0

prebid-server's request forgery vulnerability allows for possible host environment data extraction

Published
July 29, 2026
Last Modified
July 29, 2026

🔗 CVE IDs covered (1)

📋 Description

Impact

Certain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints to unauthorized access.

Patches

Patched in v4.4.0

Workarounds

If one is unable to update, please make sure that the affected bidder adapters are disabled.

🎯 Affected products4

  • go/github.com/prebid/prebid-server/v4:< 4.4.0
  • go/github.com/prebid/prebid-server/v3:<= 3.30.0
  • go/github.com/prebid/prebid-server/v2:<= 2.32.0
  • go/github.com/prebid/prebid-server:<= 0.275.0

🔗 References (5)