CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-54735

CVE-2026-54735: Critical Server-Side Request Forgery (SSRF) in Prebid Server Bidder Adapters

Alon Barad
Alon Barad
Software Engineer

Jul 29, 2026·6 min read·87 visits

Executive Summary (TL;DR)

Prebid Server versions prior to 4.4.0 fail to validate or sanitize dynamic host and subdomain parameters within several bidder adapters. This allows unauthenticated remote attackers to manipulate the destination of outbound HTTP requests by supplying control characters in OpenRTB requests.

CVE-2026-54735 is a critical Server-Side Request Forgery (SSRF) vulnerability in Prebid Server's bidder adapters, allowing unauthenticated remote attackers to route HTTP requests to arbitrary locations, including internal local host loopbacks and cloud provider metadata endpoints.

Vulnerability Overview

Prebid Server is a cloud-based server-side header bidding platform designed to execute real-time ad auctions. To fetch bids, it communicates with multiple downstream advertising endpoints through dedicated bidder adapters. The application exposes endpoints like /openrtb2/auction to ingest publisher-supplied OpenRTB bid request structures.

Prior to version 4.4.0, the server-side request architecture did not enforce proper security boundaries on parameters provided within the bid request object. Specifically, multiple bidder adapters accepted dynamically configured connection endpoints, subdomains, and hostnames directly from unauthenticated API clients.

Because these adapters trusted client-supplied input without parsing or validation, they allowed attackers to manipulate outbound transport requests. The resulting Server-Side Request Forgery (SSRF) vulnerability, tracked as CVE-2026-54735, carries a CVSS base score of 10.0 and allows unauthenticated remote attackers to control the target authority of internal outbound HTTP calls.

Root Cause Analysis

The root cause of CVE-2026-54735 lies in the handling of dynamic bidder-specific parameters inside the OpenRTB imp[].ext.<bidder> path. Certain bidder adapters require custom routing parameters, such as host, account, zone, endpoint, or pbsHost, to dynamically direct bid queries to partner-specific geographic clusters or instances.

During the request-building phase, affected adapters used Go-based macro expansion or simple string concatenation to construct outbound target URLs. The core implementation invoked functions like macros.ResolveMacros with the user-supplied string directly populated into the template. No validation or character-class restriction was enforced on these string parameters before their insertion into the URL template.

When an adapter processes a template like https://{{.Host}}.bidding-service.com/rtb, the parser expects a simple subdomain. However, if the Host value contains path-traversal characters, query separators, or fragment specifiers, the underlying URL parser redirects the destination authority. Characters like /, ?, #, or @ allow an attacker to redefine the protocol host and path components of the generated URL, completely overriding the intended destination.

Code-Level Patch Analysis

The patch introduced a defense-in-depth approach spanning strict regular expression validation and JSON schema restrictions. The core security logic was added to a new helper module in util/urlutil/security.go to provide deterministic validation of host strings.

package urlutil
 
import "regexp"
 
// safeHostPattern restricts host strings to alphanumeric characters, dots, and hyphens,
// with an optional port number suffix.
var safeHostPattern = regexp.MustCompile(`^[a-zA-Z0-9.-]+(:[0-9]+)?$`)
 
// IsSafeHost evaluates if the input contains only valid domain/IP and port syntax.
// It rejects characters like '/', '?', '#', '@', or protocol schemes.
func IsSafeHost(host string) bool {
	return safeHostPattern.MatchString(host)
}

This validation pattern prevents any injection of control characters. Individual bidder adapters were refactored to intercept input. For example, the AcuityAds adapter in adapters/acuityads/acuityads.go was updated to reject requests before resolving the endpoint macro.

// adapters/acuityads/acuityads.go
func (a *AcuityAdsAdapter) buildEndpointURL(params *openrtb_ext.ExtAcuityAds) (string, error) {
+	if !urlutil.IsSafeHost(params.Host) {
+		return "", &errortypes.BadInput{Message: "Invalid Host"}
+	}
	endpointParams := macros.EndpointTemplateParams{Host: params.Host, AccountID: params.AccountID}
	return macros.ResolveMacros(a.endpoint, endpointParams)
}

Additionally, JSON schemas were updated to block invalid inputs at the initial parsing layer. In static/bidder-params/acuityads.json, the property definition was hardened.

{
  "host": {
    "type": "string",
    "description": "Network host to send request",
    "minLength": 1,
    "pattern": "^[a-zA-Z0-9.-]+(:[0-9]+)?$"
  }
}

Exploitation & Proof-of-Concept Analysis

Exploitation of CVE-2026-54735 is straightforward and does not require active authentication sessions. An attacker targets the /openrtb2/auction endpoint of a vulnerable Prebid Server deployment and submits an OpenRTB payload referencing an affected adapter.

By supplying an input value like evil.com/path?redirect=http://attacker.com# for the host parameter of the acuityads adapter, the resulting outbound request is redirected to the attacker's server. The trailing path .bidding-service.com/rtb is discarded because the fragment character # designates it as a client-side fragment rather than part of the request path.

An alternative variation leverages the vulnerability to query local endpoints or metadata services. If the host parameter is set to localhost:8080, the Prebid Server's outbound HTTP client will target internal administrative services. Because Prebid Server is often deployed inside container environments, this enables host reconnaissance and connection manipulation.

Impact & Risk Assessment

The impact of this vulnerability is critical, leading to a complete compromise of the outbound trust boundary. A successful attack allows unauthenticated remote request forgery against any network service reachable by the Prebid Server instance.

In containerized environments such as Kubernetes or cloud provider instances (AWS, GCP, Azure), the Prebid Server can be leveraged to query the cloud metadata service. On AWS, for instance, targeting 169.254.169.254 could expose sensitive temporary credentials, IAM roles, and configuration parameters if the IMDSv1 interface is enabled.

Furthermore, this vulnerability acts as a pipeline to bypass network perimeters. Attackers can perform internal port scanning, trigger state changes on internal microservices that lack authentication, or exfiltrate local environment information. Due to the wide distribution of Prebid Server in the ad tech ecosystem, the potential exposure across ad exchanges is broad.

Fix Completeness & Limitations

While the introduced validation checks successfully mitigate syntax injection vectors, they are not a complete security solution against all forms of SSRF. The regular expression check ^[a-zA-Z0-9.-]+(:[0-9]+)?$ evaluates the syntax of the input, but it does not resolve the hostname to verify its target network.

Consequently, the patch does not prevent an attacker from supplying an authorized syntax that points to an unauthorized destination. Inputting 127.0.0.1, localhost, or private network addresses (such as 10.0.0.1) is syntactically valid under this regex and will pass the Go and JSON schema checks.

To guarantee complete protection, the application layer checks must be complemented by transport-layer restrictions. Without strict IP blocklisting on the outbound dialer of the Go HTTP client, DNS rebinding attacks and direct internal routing are still possible. Security teams must ensure that outbound network connections are restricted at the operating system or gateway level.

Official Patches

prebidValidation checks on host and subdomain parameters
prebidValidation checks commit

Fix Analysis (1)

Technical Appendix

CVSS Score
10.0/ 10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H

Affected Systems

Prebid Server

Affected Versions Detail

Product
Affected Versions
Fixed Version
prebid-server
prebid
< 4.4.04.4.0
AttributeDetail
CWE IDCWE-918
Attack VectorNetwork
CVSS v3.110.0 (Critical)
Exploit StatusProof of Concept available
CISA KEV StatusNot listed
ImpactServer-Side Request Forgery, Local Host Enumeration, Credential Disclosure

MITRE ATT&CK Mapping

T1190Exploit Public-Facing Application
Initial Access
T1005Data from Local System
Collection
CWE-918
Server-Side Request Forgery (SSRF)

The web application receives a user-supplied URL or host parameters, fails to properly validate, restrict, or sanitize the input, and subsequently issues an outbound request to that destination.

Known Exploits & Detection

GitHub security advisory test casesJSON test vectors demonstrating invalid-host.json and invalid-account.json structures used to verify the fixes in AcuityAds and Adhese adapters.

Vulnerability Timeline

Fix commit merged to prebid-server main branch
2026-06-05
Prebid Server version 4.4.0 containing the fix is released
2026-06-15
GitHub Security Advisory published
2026-07-29
CVE-2026-54735 assigned and listed publicly
2026-07-29

References & Sources

  • [1]GitHub Security Advisory GHSA-4p3g-4hcj-wpvx

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 1 hour ago•CVE-2026-102277
5.3

CVE-2026-102277: Denial of Service via Quadratic Algorithmic Complexity in brace-expansion

An uncontrolled resource consumption vulnerability exists in the brace-expansion JavaScript library. Due to an algorithmic flaw in parsing a legacy Bash-compatibility quirk involving {a},b}-shaped expansion structures, untrusted inputs containing many trailing closing braces trigger successive full-input rescans. This behavior yields quadratic CPU time complexity and high memory overhead, allowing remote, unauthenticated attackers to cause a Denial of Service (DoS) by blocking the single-threaded Node.js event loop.

Amit Schendel
Amit Schendel
3 views•7 min read
•about 2 hours ago•CVE-2026-17495
5.9

CVE-2026-17495: Path Traversal via Type Confusion in Moment.js Dynamic Locale Loading

Moment.js versions 2.29.2 through 2.30.1 are vulnerable to a Path Traversal flaw (CWE-27) on server-side Node.js environments when dynamic locales are configured. The vulnerability stems from an object-coercion bypass in the locale-name sanitization routine, which assumes incoming variables are string primitives. An attacker can pass a structured object with custom 'match' and 'toString' properties to bypass regex-based directory checks, leading to arbitrary file loading via Node's internal 'require()' call.

Amit Schendel
Amit Schendel
5 views•6 min read
•about 4 hours ago•CVE-2026-101911
6.3

CVE-2026-101911: Denial of Service via Uncontrolled Resource Consumption in ip-address Library

A denial-of-service vulnerability exists in the ip-address npm package prior to version 10.7.1. The library fails to limit the length of input strings parsed by the Address4 and Address6 constructors. When parsing highly malformed addresses, the diagnostic parser runs a synchronous regular expression search-and-replace that generates descriptive HTML error messages. Passing an excessively long string containing invalid characters causes severe memory amplification and CPU starvation, resulting in a thread hang or process crash in Node.js applications.

Amit Schendel
Amit Schendel
4 views•7 min read
•about 5 hours ago•CVE-2026-101912
6.3

CVE-2026-101912: Cross-Family IP Address Subnet Containment Logic Bypass in ip-address Library

The ip-address library is vulnerable to a logical bypass in its subnet containment methods. The functions isInSubnet() and isHostInSubnet() do not verify that compared addresses belong to the same IP family before performing masking checks. Under specific circumstances, an IPv6 address can share leading bit patterns with an IPv4 subnet, causing the containment check to evaluate as true. This allows attackers to bypass access control lists, firewalls, and server-side request forgery protection layers in applications relying on the library.

Amit Schendel
Amit Schendel
6 views•6 min read
•about 6 hours ago•CVE-2026-101894
9.1

CVE-2026-101894: Arbitrary File Read/Write via Symbolic Link Chaining in @xhmikosr/decompress

CVE-2026-101894 is a critical path traversal vulnerability in @xhmikosr/decompress before versions 10.2.2 and 11.1.4, stemming from an incomplete hardening bypass of CVE-2026-53486 where static lexical containment checks fail to detect kernel-level resolution of crafted symlink chains, allowing arbitrary local file modification and execution.

Amit Schendel
Amit Schendel
5 views•7 min read
•about 7 hours ago•CVE-2026-86818
4.8

CVE-2026-86818: Mailto Header Injection via Percent-Encoded Field-Name Desynchronization in fast-uri

A security-critical desynchronization vulnerability exists in fast-uri versions 4.1.3 and 4.1.4. Due to incorrect order-of-operations, the mailto scheme parser validates raw percent-encoded parameter keys instead of normalized keys, but subsequently decodes and writes them into a generic headers object. When the parsed URI is serialized, these keys are re-emitted literally, allowing attackers to bypass validation boundaries and smuggle unauthorized recipients, subjects, or body parameters in downstream mailing applications.

Amit Schendel
Amit Schendel
7 views•6 min read