{"id":"GHSA-4p3g-4hcj-wpvx","summary":"prebid-server's request forgery vulnerability allows for possible host environment data extraction","details":"### Impact\nCertain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints to unauthorized access.\n\n### Patches\nPatched in [v4.4.0](https://github.com/prebid/prebid-server/releases/tag/v4.4.0)\n\n### Workarounds\nIf one is unable to update, please make sure that the affected bidder adapters are disabled.","aliases":["CVE-2026-54735","GO-2026-6139"],"modified":"2026-08-18T17:23:47.704399899Z","published":"2026-07-29T16:00:36Z","database_specific":{"severity":"CRITICAL","github_reviewed":true,"github_reviewed_at":"2026-07-29T16:00:36Z","nvd_published_at":null,"cwe_ids":["CWE-918"]},"references":[{"type":"WEB","url":"https://github.com/prebid/prebid-server/security/advisories/GHSA-4p3g-4hcj-wpvx"},{"type":"WEB","url":"https://github.com/prebid/prebid-server/pull/4802"},{"type":"WEB","url":"https://github.com/prebid/prebid-server/commit/494ac271cd4b5024df9123ef25ca3cff96390be3"},{"type":"PACKAGE","url":"https://github.com/prebid/prebid-server"},{"type":"WEB","url":"https://github.com/prebid/prebid-server/releases/tag/v4.4.0"}],"affected":[{"package":{"name":"github.com/prebid/prebid-server/v4","ecosystem":"Go","purl":"pkg:golang/github.com/prebid/prebid-server/v4"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"4.4.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-4p3g-4hcj-wpvx/GHSA-4p3g-4hcj-wpvx.json"}},{"package":{"name":"github.com/prebid/prebid-server/v3","ecosystem":"Go","purl":"pkg:golang/github.com/prebid/prebid-server/v3"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"3.30.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-4p3g-4hcj-wpvx/GHSA-4p3g-4hcj-wpvx.json"}},{"package":{"name":"github.com/prebid/prebid-server/v2","ecosystem":"Go","purl":"pkg:golang/github.com/prebid/prebid-server/v2"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"2.32.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-4p3g-4hcj-wpvx/GHSA-4p3g-4hcj-wpvx.json"}},{"package":{"name":"github.com/prebid/prebid-server","ecosystem":"Go","purl":"pkg:golang/github.com/prebid/prebid-server"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"0.275.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-4p3g-4hcj-wpvx/GHSA-4p3g-4hcj-wpvx.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"}]}