Junglewise Threat Intelligence

CVE-2026-54734: Prebid Server Java SSRF in bidder adapters

CVE-2026-54734 · Severity: critical · CVSS 10 · Published 2026-09-17

Executive brief

Prebid Server Java is a programmatic ad bidding platform used by publishers and advertisers to manage real-time bidding auctions. Before version 3.43.0, the system fails to validate user-supplied parameters when constructing outbound HTTP requests to ad bidders, allowing an attacker to redirect those requests to internal networks, metadata endpoints, or other sensitive services on the server's own infrastructure. This could expose internal systems or enable lateral movement attacks.

Technical details

This is a Server-Side Request Forgery (SSRF) vulnerability in Prebid Server Java's bidder adapter implementations. Certain bidder adapters interpolate untrusted user-supplied parameters (particularly domain and path components) directly into outbound request URLs without validation using the HttpUtil.validateDomainName() utility. An attacker who can control bid-request parameters can craft URLs pointing to internal network services, cloud metadata endpoints, or other sensitive server infrastructure. The vulnerability requires network access to the Prebid Server and the ability to submit bid requests with malicious parameters. The fix, released in version 3.43.0, adds mandatory HttpUtil validation to domain and path parameters before URL construction.

Affected products

  • Prebid Prebid Server Java prior to 3.43.0

Timeline

  • 2026-09-17: disclosed
  • 2026-05-29: patched

References