原始 OSV JSON{
"id": "GHSA-4p3g-4hcj-wpvx",
"aliases": [
"CVE-2026-54735"
],
"details": "### Impact\nCertain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints to unauthorized access.\n\n### Patches\nPatched in [v4.4.0](https://github.com/prebid/prebid-server/releases/tag/v4.4.0)\n\n### Workarounds\nIf one is unable to update, please make sure that the affected bidder adapters are disabled.",
"summary": "prebid-server's request forgery vulnerability allows for possible host environment data extraction",
"affected": [
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"fixed": "4.4.0"
}
]
}
],
"package": {
"name": "github.com/prebid/prebid-server/v4",
"ecosystem": "Go"
}
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"last_affected": "3.30.0"
}
]
}
],
"package": {
"name": "github.com/prebid/prebid-server/v3",
"ecosystem": "Go"
}
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"last_affected": "2.32.0"
}
]
}
],
"package": {
"name": "github.com/prebid/prebid-server/v2",
"ecosystem": "Go"
}
},
{
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "0"
},
{
"last_affected": "0.275.0"
}
]
}
],
"package": {
"name": "github.com/prebid/prebid-server",
"ecosystem": "Go"
}
}
],
"modified": "2026-07-29T16:00:36Z",
"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H"
}
],
"published": "2026-07-29T16:00:36Z",
"references": [
{
"url": "https://github.com/prebid/prebid-server/security/advisories/GHSA-4p3g-4hcj-wpvx",
"type": "WEB"
},
{
"url": "https://github.com/prebid/prebid-server/pull/4802",
"type": "WEB"
},
{
"url": "https://github.com/prebid/prebid-server/commit/494ac271cd4b5024df9123ef25ca3cff96390be3",
"type": "WEB"
},
{
"url": "https://github.com/prebid/prebid-server",
"type": "PACKAGE"
},
{
"url": "https://github.com/prebid/prebid-server/releases/tag/v4.4.0",
"type": "WEB"
}
],
"schema_version": "1.4.0",
"database_specific": {
"cwe_ids": [
"CWE-918"
],
"severity": "CRITICAL",
"github_reviewed": true,
"nvd_published_at": null,
"github_reviewed_at": "2026-07-29T16:00:36Z"
}
}