Jul 29, 2026·6 min read·87 visits
Prebid Server versions prior to 4.4.0 fail to validate or sanitize dynamic host and subdomain parameters within several bidder adapters. This allows unauthenticated remote attackers to manipulate the destination of outbound HTTP requests by supplying control characters in OpenRTB requests.
CVE-2026-54735 is a critical Server-Side Request Forgery (SSRF) vulnerability in Prebid Server's bidder adapters, allowing unauthenticated remote attackers to route HTTP requests to arbitrary locations, including internal local host loopbacks and cloud provider metadata endpoints.
Prebid Server is a cloud-based server-side header bidding platform designed to execute real-time ad auctions. To fetch bids, it communicates with multiple downstream advertising endpoints through dedicated bidder adapters. The application exposes endpoints like /openrtb2/auction to ingest publisher-supplied OpenRTB bid request structures.
Prior to version 4.4.0, the server-side request architecture did not enforce proper security boundaries on parameters provided within the bid request object. Specifically, multiple bidder adapters accepted dynamically configured connection endpoints, subdomains, and hostnames directly from unauthenticated API clients.
Because these adapters trusted client-supplied input without parsing or validation, they allowed attackers to manipulate outbound transport requests. The resulting Server-Side Request Forgery (SSRF) vulnerability, tracked as CVE-2026-54735, carries a CVSS base score of 10.0 and allows unauthenticated remote attackers to control the target authority of internal outbound HTTP calls.
The root cause of CVE-2026-54735 lies in the handling of dynamic bidder-specific parameters inside the OpenRTB imp[].ext.<bidder> path. Certain bidder adapters require custom routing parameters, such as host, account, zone, endpoint, or pbsHost, to dynamically direct bid queries to partner-specific geographic clusters or instances.
During the request-building phase, affected adapters used Go-based macro expansion or simple string concatenation to construct outbound target URLs. The core implementation invoked functions like macros.ResolveMacros with the user-supplied string directly populated into the template. No validation or character-class restriction was enforced on these string parameters before their insertion into the URL template.
When an adapter processes a template like https://{{.Host}}.bidding-service.com/rtb, the parser expects a simple subdomain. However, if the Host value contains path-traversal characters, query separators, or fragment specifiers, the underlying URL parser redirects the destination authority. Characters like /, ?, #, or @ allow an attacker to redefine the protocol host and path components of the generated URL, completely overriding the intended destination.
The patch introduced a defense-in-depth approach spanning strict regular expression validation and JSON schema restrictions. The core security logic was added to a new helper module in util/urlutil/security.go to provide deterministic validation of host strings.
package urlutil
import "regexp"
// safeHostPattern restricts host strings to alphanumeric characters, dots, and hyphens,
// with an optional port number suffix.
var safeHostPattern = regexp.MustCompile(`^[a-zA-Z0-9.-]+(:[0-9]+)?$`)
// IsSafeHost evaluates if the input contains only valid domain/IP and port syntax.
// It rejects characters like '/', '?', '#', '@', or protocol schemes.
func IsSafeHost(host string) bool {
return safeHostPattern.MatchString(host)
}This validation pattern prevents any injection of control characters. Individual bidder adapters were refactored to intercept input. For example, the AcuityAds adapter in adapters/acuityads/acuityads.go was updated to reject requests before resolving the endpoint macro.
// adapters/acuityads/acuityads.go
func (a *AcuityAdsAdapter) buildEndpointURL(params *openrtb_ext.ExtAcuityAds) (string, error) {
+ if !urlutil.IsSafeHost(params.Host) {
+ return "", &errortypes.BadInput{Message: "Invalid Host"}
+ }
endpointParams := macros.EndpointTemplateParams{Host: params.Host, AccountID: params.AccountID}
return macros.ResolveMacros(a.endpoint, endpointParams)
}Additionally, JSON schemas were updated to block invalid inputs at the initial parsing layer. In static/bidder-params/acuityads.json, the property definition was hardened.
{
"host": {
"type": "string",
"description": "Network host to send request",
"minLength": 1,
"pattern": "^[a-zA-Z0-9.-]+(:[0-9]+)?$"
}
}Exploitation of CVE-2026-54735 is straightforward and does not require active authentication sessions. An attacker targets the /openrtb2/auction endpoint of a vulnerable Prebid Server deployment and submits an OpenRTB payload referencing an affected adapter.
By supplying an input value like evil.com/path?redirect=http://attacker.com# for the host parameter of the acuityads adapter, the resulting outbound request is redirected to the attacker's server. The trailing path .bidding-service.com/rtb is discarded because the fragment character # designates it as a client-side fragment rather than part of the request path.
An alternative variation leverages the vulnerability to query local endpoints or metadata services. If the host parameter is set to localhost:8080, the Prebid Server's outbound HTTP client will target internal administrative services. Because Prebid Server is often deployed inside container environments, this enables host reconnaissance and connection manipulation.
The impact of this vulnerability is critical, leading to a complete compromise of the outbound trust boundary. A successful attack allows unauthenticated remote request forgery against any network service reachable by the Prebid Server instance.
In containerized environments such as Kubernetes or cloud provider instances (AWS, GCP, Azure), the Prebid Server can be leveraged to query the cloud metadata service. On AWS, for instance, targeting 169.254.169.254 could expose sensitive temporary credentials, IAM roles, and configuration parameters if the IMDSv1 interface is enabled.
Furthermore, this vulnerability acts as a pipeline to bypass network perimeters. Attackers can perform internal port scanning, trigger state changes on internal microservices that lack authentication, or exfiltrate local environment information. Due to the wide distribution of Prebid Server in the ad tech ecosystem, the potential exposure across ad exchanges is broad.
While the introduced validation checks successfully mitigate syntax injection vectors, they are not a complete security solution against all forms of SSRF. The regular expression check ^[a-zA-Z0-9.-]+(:[0-9]+)?$ evaluates the syntax of the input, but it does not resolve the hostname to verify its target network.
Consequently, the patch does not prevent an attacker from supplying an authorized syntax that points to an unauthorized destination. Inputting 127.0.0.1, localhost, or private network addresses (such as 10.0.0.1) is syntactically valid under this regex and will pass the Go and JSON schema checks.
To guarantee complete protection, the application layer checks must be complemented by transport-layer restrictions. Without strict IP blocklisting on the outbound dialer of the Go HTTP client, DNS rebinding attacks and direct internal routing are still possible. Security teams must ensure that outbound network connections are restricted at the operating system or gateway level.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H| Product | Affected Versions | Fixed Version |
|---|---|---|
prebid-server prebid | < 4.4.0 | 4.4.0 |
| Attribute | Detail |
|---|---|
| CWE ID | CWE-918 |
| Attack Vector | Network |
| CVSS v3.1 | 10.0 (Critical) |
| Exploit Status | Proof of Concept available |
| CISA KEV Status | Not listed |
| Impact | Server-Side Request Forgery, Local Host Enumeration, Credential Disclosure |
The web application receives a user-supplied URL or host parameters, fails to properly validate, restrict, or sanitize the input, and subsequently issues an outbound request to that destination.
An uncontrolled resource consumption vulnerability exists in the brace-expansion JavaScript library. Due to an algorithmic flaw in parsing a legacy Bash-compatibility quirk involving {a},b}-shaped expansion structures, untrusted inputs containing many trailing closing braces trigger successive full-input rescans. This behavior yields quadratic CPU time complexity and high memory overhead, allowing remote, unauthenticated attackers to cause a Denial of Service (DoS) by blocking the single-threaded Node.js event loop.
Moment.js versions 2.29.2 through 2.30.1 are vulnerable to a Path Traversal flaw (CWE-27) on server-side Node.js environments when dynamic locales are configured. The vulnerability stems from an object-coercion bypass in the locale-name sanitization routine, which assumes incoming variables are string primitives. An attacker can pass a structured object with custom 'match' and 'toString' properties to bypass regex-based directory checks, leading to arbitrary file loading via Node's internal 'require()' call.
A denial-of-service vulnerability exists in the ip-address npm package prior to version 10.7.1. The library fails to limit the length of input strings parsed by the Address4 and Address6 constructors. When parsing highly malformed addresses, the diagnostic parser runs a synchronous regular expression search-and-replace that generates descriptive HTML error messages. Passing an excessively long string containing invalid characters causes severe memory amplification and CPU starvation, resulting in a thread hang or process crash in Node.js applications.
The ip-address library is vulnerable to a logical bypass in its subnet containment methods. The functions isInSubnet() and isHostInSubnet() do not verify that compared addresses belong to the same IP family before performing masking checks. Under specific circumstances, an IPv6 address can share leading bit patterns with an IPv4 subnet, causing the containment check to evaluate as true. This allows attackers to bypass access control lists, firewalls, and server-side request forgery protection layers in applications relying on the library.
CVE-2026-101894 is a critical path traversal vulnerability in @xhmikosr/decompress before versions 10.2.2 and 11.1.4, stemming from an incomplete hardening bypass of CVE-2026-53486 where static lexical containment checks fail to detect kernel-level resolution of crafted symlink chains, allowing arbitrary local file modification and execution.
A security-critical desynchronization vulnerability exists in fast-uri versions 4.1.3 and 4.1.4. Due to incorrect order-of-operations, the mailto scheme parser validates raw percent-encoded parameter keys instead of normalized keys, but subsequently decodes and writes them into a generic headers object. When the parsed URI is serialized, these keys are re-emitted literally, allowing attackers to bypass validation boundaries and smuggle unauthorized recipients, subjects, or body parameters in downstream mailing applications.