← Back to browse · API

CVE-2026-54735

Severity
CRITICAL
CVSS
10.0
EPSS
0.00351
Risk score
40.12
CISA KEV
No
PoC
No
Published
2026-07-29
Modified
2026-07-29
First seen
2026-08-05
Aliases
EUVD-2026-50401, GHSA-4P3G-4HCJ-WPVX
Products
prebid:prebid-server < 4.4.0
Sources
nvd CVE-2026-54735
euvd EUVD-2026-50401

Description

Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in Prebid Server interpolate user-supplied parameters into outbound request URLs without properly validating host and subdomain values, allowing crafted bid request parameters to cause server-side requests to unintended destinations and potentially expose internal network services or sensitive server endpoints. This issue is fixed in version 4.4.0.

References