CRITICAL
10.0 CVE-2026-54734 Published 17 Sept 2026
Prebid Server Java Bidder Adapter URL Injection
Worried this affects your website?
Prebid Server Java, prior to 3.43.0, had a vulnerability in certain bidder adapters.
These adapters interpolated user-supplied parameters into outbound request URLs without proper validation, allowing a malicious actor to manipulate the server into sending HTTP requests to unintended destinations.
- Impact: Potential access to internal network services, metadata endpoints, or other sensitive server endpoints.
- Fixed in: 3.43.0
Reference: CVE-2026-54734 on NVD
← Back to Security News