THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-4p3g-4hcj-wpvx (critical) — prebid-server's request forgery vulnerability allows for possible host environment data extraction

[GHSA] GHSA-4p3g-4hcj-wpvx (critical) — prebid-server's request forgery vulnerability allows for possible host environment data extraction

medgithub_advisoriesPublished 2026-07-29

GHSA-4p3g-4hcj-wpvx Severity: critical CVE: CVE-2026-54735

prebid-server's request forgery vulnerability allows for possible host environment data extraction

### Impact Certain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP re

Indicators of compromise

Original source: https://github.com/advisories/GHSA-4p3g-4hcj-wpvx