Impact
Prebid Server Java versions prior to 3.43.0 can interpolate user‑supplied parameters into outbound request URLs without proper domain or path validation. A malicious actor who can craft bid‑request parameters may cause the server to send HTTP requests to unintended destinations, potentially reaching internal network services, metadata endpoints, or other sensitive server endpoints with the server’s network access. The consequence is the ability to read secrets or metadata not intended for external exposure, resulting in data leakage and possible compromise of the host environment.
Affected Systems
The vulnerability affects Prebid Server Java from its early releases up to and including version 3.42.x. Any deployment of Prebid Server Java that has not been updated to version 3.43.0 or later is susceptible. The affected product is the entire Prebid Server Java stack, regardless of deployment size or configuration.
Risk and Exploitability
The CVSS score of 10 indicates a critical severity level. Although the EPSS score is less than 1%, indicating a low probability of exploitation at this time, the flaw remains exploitable if an attacker can supply bid‑request parameters, such as through a malicious ad network or compromised user traffic. The vulnerability is not currently listed in the CISA KEV catalog, but its potential to reach internal services makes it a high‑risk target for attackers seeking to exfiltrate host‑level information. The attack vector is inferred to be remote, contingent on the ability to influence the contents of bid requests sent to the Prebid Server.
OpenCVE Enrichment