CRITICAL 10.0 CVE-2026-54734 Published 17 Sept 2026

Prebid Server Java Bidder Adapter URL Injection

Worried this affects your website?

Prebid Server Java, prior to 3.43.0, had a vulnerability in certain bidder adapters.

These adapters interpolated user-supplied parameters into outbound request URLs without proper validation, allowing a malicious actor to manipulate the server into sending HTTP requests to unintended destinations.

  • Impact: Potential access to internal network services, metadata endpoints, or other sensitive server endpoints.
  • Fixed in: 3.43.0

Reference: CVE-2026-54734 on NVD

← Back to Security News