GHSA-4p3g-4hcj-wpvx

Suggest an improvement
Source
https://github.com/advisories/GHSA-4p3g-4hcj-wpvx
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-4p3g-4hcj-wpvx/GHSA-4p3g-4hcj-wpvx.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-4p3g-4hcj-wpvx
Aliases
Published
2026-07-29T16:00:36Z
Modified
2026-08-18T17:23:47Z
Severity
  • 10.0 (Critical) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H CVSS Calculator
Summary
prebid-server's request forgery vulnerability allows for possible host environment data extraction
Details

Impact

Certain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints to unauthorized access.

Patches

Patched in v4.4.0

Workarounds

If one is unable to update, please make sure that the affected bidder adapters are disabled.

Database specific
{
    "cwe_ids": [
        "CWE-918"
    ],
    "github_reviewed": true,
    "github_reviewed_at": "2026-07-29T16:00:36Z",
    "nvd_published_at": null,
    "severity": "CRITICAL"
}
References

Affected packages

Go
github.com/prebid/prebid-server/v4

Package

Name
github.com/prebid/prebid-server/v4
View open source insights on deps.dev
Purl
pkg:golang/github.com/prebid/prebid-server/v4

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
4.4.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-4p3g-4hcj-wpvx/GHSA-4p3g-4hcj-wpvx.json"
github.com/prebid/prebid-server/v3

Package

Name
github.com/prebid/prebid-server/v3
View open source insights on deps.dev
Purl
pkg:golang/github.com/prebid/prebid-server/v3

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
3.30.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-4p3g-4hcj-wpvx/GHSA-4p3g-4hcj-wpvx.json"
github.com/prebid/prebid-server/v2

Package

Name
github.com/prebid/prebid-server/v2
View open source insights on deps.dev
Purl
pkg:golang/github.com/prebid/prebid-server/v2

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
2.32.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-4p3g-4hcj-wpvx/GHSA-4p3g-4hcj-wpvx.json"
github.com/prebid/prebid-server

Package

Name
github.com/prebid/prebid-server
View open source insights on deps.dev
Purl
pkg:golang/github.com/prebid/prebid-server

Affected ranges

Type
SEMVER
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Last Affected
0.275.0

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/07/GHSA-4p3g-4hcj-wpvx/GHSA-4p3g-4hcj-wpvx.json"