What is CVE-2026-54735?
Vulnerability in Prebid Server allows certain bidder adapters to interpolate user-supplied host and subdomain values into outbound request URLs without proper validation. Versions prior to 4.4.0 are affected, potentially enabling manipulation of real-time ad auction requests. Upgrading to version 4.4.0 or later is required to mitigate this risk.
Azərbaycanca: Prebid Server-də aşkarlanmış bu boşluq bəzi bidder adapterlərinin istifadəçi tərəfindən təqdim olunan host və subdomain dəyərlərini çıxan sorğu URL-lərinə düzgün validasiya etmədən daxil etməsinə imkan verir. 4.4.0 versiyasından əvvəlki versiyalar təsirə məruz qalır; istismar hücumçuya real vaxt reklam auksion sorğularını manipulyasiya etməyə imkan yaradır. Bu boşluqdan qorunmaq üçün dərhal 4.4.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of Prebid Server are affected by CVE-2026-54735?
This vulnerability affects all versions of Prebid Server prior to 4.4.0.
What action is required to mitigate CVE-2026-54735?
Upgrading to Prebid Server version 4.4.0 or later is required to mitigate the risk.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.