{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/prebid/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["prebid-server"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Prebid"],"content_html":"\u003cp\u003ePrebid Server is affected by a Server-Side Request Forgery (SSRF) vulnerability identified as CVE-2026-54735. The flaw originates in certain bidder adapters that fail to perform adequate input validation on user-supplied parameters before interpolating them into outbound request URLs. An attacker can supply malicious parameters in a bid request to force the Prebid Server instance to send HTTP requests to arbitrary destinations. This vulnerability enables attackers to perform reconnaissance on the internal network, interact with sensitive local endpoints, or exfiltrate metadata from the host environment. The vulnerability impacts Prebid Server versions prior to v4.4.0, as well as specific older release branches. Defenders should prioritize patching or disabling affected bidder adapters to mitigate unauthorized internal access.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an unauthenticated attacker to abuse the server as a proxy to reach internal resources that are otherwise inaccessible from the public internet. This can lead to the exposure of internal metadata services (e.g., cloud instance metadata), local administrative interfaces, or sensitive internal API endpoints. The severity is critical given the potential for unauthorized data extraction and lateral movement within the network hosting the Prebid Server instance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade Prebid Server to version v4.4.0 or later to apply the necessary input validation logic.\u003c/li\u003e\n\u003cli\u003eDisable any bidder adapters known to be susceptible to parameter injection if patching cannot be performed immediately.\u003c/li\u003e\n\u003cli\u003eImplement egress filtering on the network hosting Prebid Server to restrict outbound connections to only verified and expected external bidder endpoints.\u003c/li\u003e\n\u003cli\u003eAudit web server logs and proxy logs for anomalous HTTP requests originating from the Prebid Server application to internal IP ranges (e.g., 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) or local loopback addresses.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-29T16:01:08Z","date_published":"2026-07-29T16:01:08Z","id":"https://feed.craftedsignal.io/briefs/2026-07-prebid-server-ssrf/","summary":"Prebid Server contains a Server-Side Request Forgery vulnerability (CVE-2026-54735) allowing unauthenticated attackers to force the server to perform arbitrary outbound HTTP requests.","title":"Prebid Server SSRF Vulnerability in Bidder Adapters","url":"https://feed.craftedsignal.io/briefs/2026-07-prebid-server-ssrf/"}],"language":"en","title":"CraftedSignal Threat Feed - Prebid","version":"https://jsonfeed.org/version/1.1"}