Description
Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate the resulting domain or path segment. A malicious actor who can supply bid-request parameters can cause the server to send HTTP requests to unintended destinations, potentially reaching internal network services, metadata endpoints, or other sensitive server endpoints with the server's network access. This issue is fixed in version 3.43.0.
Published: 2026-09-17
Score: 10 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Potential internal network data exposure through request forgery
Action: Immediate Patch
AI Analysis

Impact

Prebid Server Java versions prior to 3.43.0 can interpolate user‑supplied parameters into outbound request URLs without proper domain or path validation. A malicious actor who can craft bid‑request parameters may cause the server to send HTTP requests to unintended destinations, potentially reaching internal network services, metadata endpoints, or other sensitive server endpoints with the server’s network access. The consequence is the ability to read secrets or metadata not intended for external exposure, resulting in data leakage and possible compromise of the host environment.

Affected Systems

The vulnerability affects Prebid Server Java from its early releases up to and including version 3.42.x. Any deployment of Prebid Server Java that has not been updated to version 3.43.0 or later is susceptible. The affected product is the entire Prebid Server Java stack, regardless of deployment size or configuration.

Risk and Exploitability

The CVSS score of 10 indicates a critical severity level. Although the EPSS score is less than 1%, indicating a low probability of exploitation at this time, the flaw remains exploitable if an attacker can supply bid‑request parameters, such as through a malicious ad network or compromised user traffic. The vulnerability is not currently listed in the CISA KEV catalog, but its potential to reach internal services makes it a high‑risk target for attackers seeking to exfiltrate host‑level information. The attack vector is inferred to be remote, contingent on the ability to influence the contents of bid requests sent to the Prebid Server.

Generated by OpenCVE AI on September 19, 2026 at 01:53 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade Prebid Server Java to version 3.43.0 or later to apply the vendor‑released fix.
  • Configure network firewall or ACL rules to block outbound HTTP requests from the Prebid Server to internal services or endpoints that are not explicitly required.
  • Implement input validation or sanitization for user‑supplied bid‑request parameters to ensure that URLs are constructed safely and that only intended domains can be called.

Generated by OpenCVE AI on September 19, 2026 at 01:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Prebid
Prebid prebid-server-java
Vendors & Products Prebid
Prebid prebid-server-java
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 17 Sep 2026 22:15:00 +0000

Type Values Removed Values Added
Description Prebid Server Java is the Java version of Prebid Server. Prior to 3.43.0, certain bidder adapters interpolate user-supplied parameters into outbound request URLs without using HttpUtil to validate the resulting domain or path segment. A malicious actor who can supply bid-request parameters can cause the server to send HTTP requests to unintended destinations, potentially reaching internal network services, metadata endpoints, or other sensitive server endpoints with the server's network access. This issue is fixed in version 3.43.0.
Title Prebid Server Java: Vulnerability to request forgery allows for possible host environment data extraction
Weaknesses CWE-918
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Prebid Prebid-server-java
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-09-18T20:03:23.515Z

Reserved: 2026-06-15T23:07:33.233Z

Link: CVE-2026-54734

cve-icon Vulnrichment

Updated: 2026-09-18T20:03:20.344Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-17T22:17:03.317

Modified: 2026-09-23T18:12:04.247

Link: CVE-2026-54734

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T02:00:13Z

Weaknesses
  • CWE-918

    Server-Side Request Forgery (SSRF)