GO · JULY 2026 · EARLY WARNING

prebid-server Package Vulnerability: Request Forgery Threat

EARLY WARNING · UNCONFIRMED. This page describes a developing threat that 0Day surfaced from early signals and has not yet independently confirmed. Details may change. Always verify against the primary sources before acting.
GHSA-4P3G-4HCJ-WPVXSeverity: HIGH

An early warning has been issued regarding a request forgery vulnerability in the prebid-server package, which may allow for host environment data extraction. Affected versions include v2, v3, and v4.

What happened

The prebid-server package is under investigation for a vulnerability that could enable request forgery, potentially leading to the extraction of host environment data. This issue arises from certain bidder adapters that accept user-supplied parameters interpolated into outbound request URLs. Without adequate input validation, a malicious actor might exploit this to direct the server to send HTTP requests to unintended destinations, risking exposure of internal network services or sensitive server endpoints.

Professional software engineers using prebid-server versions v2, v3, or v4 are advised to assess their exposure. The recommended actions include upgrading to prebid-server v4.4.0 or disabling the affected bidder adapters if an update is not feasible. For the most accurate and detailed information, consulting the primary sources is advised.

How 0Day mitigates this

MATCHED TO YOUR ACTUAL DEPENDENCY GRAPH0Day matches every incoming threat signal against your GitHub organization’s full dependency graph, including transitive dependencies. If prebid-server is anywhere in your dependency tree, the engineers who own the affected repositories get a push alert the moment it is flagged — no manual audit to remember to run.

Read how this differs from waiting on a scanner to catch a known advisory, or see the exact, read-only access 0Day needs to do this for an organization.

Join the 0Day waitlist →

← Back to all threats