User Parameter Handling Flaw in Prebid Server Java Affects Bidder Adapters
CVE-2026-54734

10CRITICAL

Key Information:

Vendor

Prebid

Vendor
CVE Published:
17 September 2026

What is CVE-2026-54734?

A critical security issue has been identified in Prebid Server Java that enables malicious actors to exploit user-supplied parameters. The flaw allows attackers to manipulate outbound request URLs without proper validation of the resulting domain or path segment. This could lead the server to inadvertently send HTTP requests to unauthorized destinations, potentially breaching internal network services, accessing sensitive metadata endpoints, or reaching other critical server resources. The vulnerability has been addressed in version 3.43.0, where enhanced validation of bid-request parameters ensures that such exploits are mitigated.

Affected Version(s)

prebid-server-java < 3.43.0

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.