External risk intelligence

Prebid Server Java Bidder Adapter Request Forgery Allows Network Access

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-54734

Prebid Server is an internet-facing component used in programmatic advertising to process bid requests. Because it is designed to receive and process external requests from various demand-side platforms and clients, the service is commonly deployed as a public-facing API endpoint, making the vulnerable adapter functionality directly reachable via the internet.

Server-Side Request Forgery

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This advisory concerns a critical vulnerability in Prebid Server Java, a component used in programmatic advertising. The issue allows attackers to craft requests that could cause the server to access unintended internal or sensitive network resources, posing a significant security risk. The main concern is confirming if our environment is using this specific technology and is exposed.

  • Server may connect to unintended network locations.
  • Protects against unauthorized access to internal systems.
  • Confirm relevance and potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker can target Prebid Server Java by submitting specially crafted bid-request parameters. These parameters are then incorporated into outgoing request URLs without proper validation. This allows an attacker to direct the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints.

  • No authentication required to send requests.
  • Malicious parameters trigger outbound requests.
  • Risk of exposing internal network services.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, Prebid Server Java could send HTTP requests to unintended destinations due to improper validation of user-supplied parameters. This could allow an attacker to reach internal network services, metadata endpoints, or other sensitive server endpoints using the server's network access.

  • Internal network services.
  • Malicious parameters in bid requests.
  • Unauthorized access to internal resources.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in Prebid Server Java could allow malicious actors to redirect internal network requests. Infrastructure and platform teams are likely responsible for managing Prebid Server deployments. The immediate priority is to identify all instances of the affected software, confirm their exposure and business criticality, and then coordinate remediation with the responsible ownership.

  • Identify all Prebid Server instances.
  • Verify network reachability and criticality.
  • Plan remediation based on identified risk.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Prebid Server Java?

Prebid Server Java is a server-side component used in programmatic advertising to manage and process real-time bidding requests. It acts as a middleman that communicates with various demand-side platforms to facilitate ad auctions. Because it handles incoming traffic from diverse partners, it is typically deployed as a high-performance Java-based engine within ad tech infrastructure to scale header bidding operations.

How does CVE-2026-54734 work?

This vulnerability is classified as Server-Side Request Forgery (CWE-918). It occurs because specific bidder adapters fail to validate user-supplied parameters before inserting them into outgoing URLs. Consequently, the server can be tricked into making HTTP requests to destinations chosen by an attacker, effectively using the server's own network identity to reach unauthorized resources.

Do I need malicious intent for this to trigger?

Yes, an attacker must specifically craft malicious bid-request parameters to exploit this weakness. The issue is not triggered by standard, legitimate advertising traffic. If the incoming request parameters do not contain the specifically crafted data designed to manipulate the outbound URL path or domain, the vulnerability remains inactive.

Is my server at risk?

Halo Surface Signal indicates that Prebid Server is frequently deployed as an internet-facing API endpoint to receive requests from global advertising partners. Because it is designed to be reachable from the internet, any instance running a version earlier than 3.43.0 is likely to be accessible to external actors who could leverage this path to reach your internal network services.

When should I update Prebid Server Java?

You should prioritize updating to version 3.43.0 immediately. After confirming your environment is running an affected version, coordinate with your infrastructure or platform engineering teams to deploy the patch. This version introduces the necessary validation logic using HttpUtil to ensure that outbound requests are restricted to intended and safe destinations.

References