GITHUB-ACTIONS · JULY 2026 · EARLY WARNING

prebid-server GitHub Action Vulnerability: Potential Data Extraction Risk

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-4P3G-4HCJ-WPVXSeverity: HIGH

prebid-server's GitHub Action is reportedly vulnerable to a request forgery attack that could allow potential data extraction from the host environment. Users of prebid-server are advised to assess their exposure.

What happened

prebid-server's GitHub Action is under investigation for a vulnerability tracked as GHSA-4P3G-4HCJ-WPVX. This issue appears to allow a request forgery attack, enabling a malicious actor to potentially extract data from the host environment. The vulnerability arises from certain bidder adapters that accept user-supplied parameters, which are interpolated into outbound request URLs without proper input validation. A crafted bid request could cause the server to send HTTP requests to unintended destinations, possibly exposing internal network services or sensitive server endpoints.

To assess your exposure, review your use of prebid-server and the specific bidder adapters in your environment. If you are using prebid-server, it is recommended to upgrade to version v4.4.0 or disable the affected bidder adapters if an upgrade is not feasible. For more detailed information, consult the GitHub Security Advisory [GHSA-4p3g-4hcj-wpvx](https://github.com/prebid/prebid-server/security/advisories/GHSA-4p3g-4hcj-wpvx).

This early warning highlights the importance of input validation in software components that handle user-supplied data. Continuous monitoring and prompt application of security updates are crucial to mitigate potential risks associated with such vulnerabilities.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If prebid-server is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats