{"id":"CVE-2026-54735","summary":"prebid-server's request forgery vulnerability allows for possible host environment data extraction","details":"Prebid Server is an open-source solution for running real-time advertising auctions in the cloud. Prior to version 4.4.0, certain bidder adapters in Prebid Server interpolate user-supplied parameters into outbound request URLs without properly validating host and subdomain values, allowing crafted bid request parameters to cause server-side requests to unintended destinations and potentially expose internal network services or sensitive server endpoints. This issue is fixed in version 4.4.0.","aliases":["GHSA-4p3g-4hcj-wpvx","GO-2026-6139"],"modified":"2026-09-09T18:26:41.610514587Z","published":"2026-07-29T15:59:46.640Z","related":["openSUSE-SU-2026:21761-1"],"database_specific":{"cwe_ids":["CWE-918"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54735.json","cna_assigner":"GitHub_M"},"references":[{"type":"WEB","url":"https://github.com/prebid/prebid-server/releases/tag/v4.4.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/54xxx/CVE-2026-54735.json"},{"type":"ADVISORY","url":"https://github.com/prebid/prebid-server/security/advisories/GHSA-4p3g-4hcj-wpvx"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-54735"},{"type":"FIX","url":"https://github.com/prebid/prebid-server/commit/494ac271cd4b5024df9123ef25ca3cff96390be3"},{"type":"FIX","url":"https://github.com/prebid/prebid-server/pull/4802"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/prebid/prebid-server","events":[{"introduced":"0"},{"fixed":"494ac271cd4b5024df9123ef25ca3cff96390be3"}],"database_specific":{"cpe":"cpe:2.3:a:prebid:prebid_server:*:*:*:*:*:go:*:*","extracted_events":[{"introduced":"0"},{"fixed":"4.4.0"}],"source":["AFFECTED_FIELD","CPE_RANGE","REFERENCES"]}}],"versions":["v4.3.0","v4.2.0","v4.1.0","v4.0.0","v3.30.0","v3.29.0","v3.28.0","v3.27.0","v3.26.0","v3.25.0","v3.24.0","v3.23.0","v3.21.0","v3.22.0","v3.20.1","v3.20.0","v3.19.0","v3.18.0","v3.17.0","v3.15.0","v3.16.0","v3.14.0","v3.13.0","v3.12.0","v3.11.0","v3.10.0","v3.9.0","v3.8.0","v3.7.0","v3.6.0","v3.5.0","v3.4.0","v3.3.0","v3.2.0","v3.1.0","v3.0.0","v2.32.0","v2.31.0","v2.30.0","v2.29.0","v2.28.0","v2.27.1","v2.27.0","v2.26.0","v2.25.1","v2.25.0","v2.24.0","v2.23.0","v2.22.0","v2.21.0","v2.20.0","v2.19.0","v2.18.0","v2.17.0","v2.16.0","v2.15.1","v2.15.0","v2.14.0","v2.13.1","v2.13.0","v2.12.0","v2.11.0","v2.10.0","v2.9.0","v2.8.0","v2.7.0","v2.6.0","v2.5.0","v2.4.0","v2.3.0","v2.2.0","v2.1.0","v2.0.2","v2.0.1","v2.0.0","v0.275.0","v0.274.0","v0.273.0","v0.272.0","v0.271.0","v0.270.0","v0.269.0","v0.268.0","v0.267.0","v0.266.0","v0.265.0","v0.264.0","v0.263.0","v0.262.1","v0.262.0","v0.261.0","v0.260.0","v0.259.0","v0.258.0","v0.257.0","v0.256.0","v0.255.0","v0.254.1","v0.254.0","v0.253.0","v0.252.0","v0.251.0","v0.250.0","v0.249.0","v0.248.0","v0.247.0","v0.246.0","v0.245.0","v0.244.0","v0.243.0","v0.242.0","v0.241.0","v0.240.0","v0.239.1","v0.239.0","v0.238.0","v0.237.0","v0.236.0","v0.235.0","v0.234.2","v0.234.1","v0.234.0","v0.233.0","v0.232.0","v0.231.0","v0.230.0","v0.229.0","v0.228.0","v0.227.2","v0.227.1","v0.227.0","v0.226.0","v0.225.0","v0.224.0","v0.223.0","v0.222.0","v0.221.0","v0.220.0","v0.219.0","v0.218.0","v0.217.0","v0.216.0","v0.215.0","v0.214.0","v0.213.0","v0.212.1","v0.212.0p","v0.212.0","v0.211.0","v0.210.0","v0.209.0","v0.208.0","v0.207.0","v0.206.1","v0.206.0","v0.205.0","v0.204.0","v0.203.0","v0.202.0","v0.201.0","v0.200.0","v0.199.0","v0.198.0","v0.197.0","v0.196.0","v0.195.0","v0.194.0","v0.193.0","v0.192.0","v0.191.0","v0.190.0","v0.189.0","v0.188.0","v0.187.0","v0.186.0","v0.185.0","v0.184.0","v0.183.0","v0.182.0","v0.181.0","v0.180.0","v0.179.0","v0.178.0","v0.177.0","v0.176.0","v0.175.0","v0.174.0","v0.173.1","v0.173.0","v0.172.0","v0.171.0","v0.170.0","v0.169.0","v0.168.0","v0.167.1","v0.167.0","v0.166.0","v0.165.0","v0.164.0","v0.163.0","v0.162.0","0.161.0","0.160.0","0.159.0","0.158.0","0.157.0","0.156.0","0.155.0","0.154.1","0.154.0","0.153.0","0.152.0","0.151.0","0.150.0","0.149.0","0.148.0","0.147.0","0.146.0","0.145.0","0.144.0","0.143.0","0.142.0","0.141.0","0.140.0","0.139.1","0.139.0","0.138.0","0.137.0","0.136.0","0.135.0","0.134.0","0.133.0","0.132.0","0.131.0","0.130.0","0.129.0","0.128.0","0.127.0","0.126.0","0.125.1","0.125.0","0.124.1","0.124.0","0.123.0","0.122.0","0.121.0","0.120.0","0.119.0","0.118.0","0.117.0","0.116.0","0.115.0","0.114.0","0.113.0","0.112.0","0.111.0","0.110.0","0.109.0","0.108.0","0.107.0","0.106.0","0.105.0","0.104.0","0.103.0","0.102.0","0.101.0","0.100.0","0.99.0","0.98.0","0.97.0","0.96.0","0.95.0","0.94.0","0.93.1","0.93.0","0.92.0","0.91.0","0.90.0","0.89.0","0.88.0","0.87.0","0.86.0","0.85.1","0.85.0","0.84.0","0.83.0","0.82.0","0.81.0","0.80.0","0.79.0","0.78.0","0.77.0","0.76.0","0.75.0","0.74.0","0.73.0","0.72.0","0.71.0","0.70.0","0.69.0","0.68.0","0.67.0","0.66.0","0.65.1","0.65.0","0.64.0","0.63.0","0.62.1","0.62.0","0.61.0","0.60.0","0.59.0","0.58.0","0.57.0","0.56.0","0.55.0","0.54.1","0.54.0","0.53.0","0.52.0","0.51.0","0.50.0","0.49.0","0.48.0","0.47.1","0.47.0","0.46.0","0.45.0","0.44.0","0.43.4","0.43.3","0.43.2","0.43.1","0.43.0","0.42.0","0.41.0","0.40.1","0.40.0","0.39.1","0.39.0","0.38.0","0.37.0","0.36.0","0.35.3","0.35.2","0.35.1","0.35.0","0.34.0","0.33.0","0.32.1","0.32.0","0.31.0","0.30.0","0.29.0","0.28.0","0.27.0","0.26.0","0.25.0","0.24.1","0.24.0","0.23.0","0.22.0","0.21.1","0.21.0","0.20.0","0.19.3","0.19.2","0.19.1","0.19.0","0.18.0","0.17.0","0.16.3","0.16.2","0.16.1","0.16.0","0.15.0","0.14.0","0.13.0","0.12.0","0.11.2","0.11.1","0.11.0","0.10.1","0.10.0","0.9.2","0.9.1","0.9.0","0.8.0","0.7.0","0.6.0","0.5.0","0.4.0","0.3.2","0.3.1","0.3.0","0.2.2","0.2.1","0.2.0","0.1.6","0.1.5","0.1.4","0.1.3","0.1.2","0.1.1","0.1.0","0.0.6","0.0.5","0.0.4","0.0.3","0.0.2","0.0.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-54735.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}