github.com/prebid/prebid-server
Open-source solution for running real-time advertising auctions in the cloud.
Activity
- Latest release
- 2y ago
- Total releases
- 20
- Cadence
- ~6 days
- Last 12 months
- 0
Reach
- Stars
- 572
Details
- First release
- May 30, 2023
| Version | Released | |
|---|---|---|
v0.275.0
minor
1 CVE
CVE-2026-54735
GHSA-4p3g-4hcj-wpvx
GO-2026-6139
Jul 29, 2026
prebid-server's request forgery vulnerability allows for possible host environment data extraction
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactCertain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints to unauthorized access. PatchesPatched in v4.4.0 WorkaroundsIf one is unable to update, please make sure that the affected bidder adapters are disabled. References
Updated Aug 18, 2026 · Source: OSV.dev |
v0.275.0
minor
Dependencies (33)
+ 25 more |
|
v0.274.0
minor
1 CVE
CVE-2026-54735
GHSA-4p3g-4hcj-wpvx
GO-2026-6139
Jul 29, 2026
prebid-server's request forgery vulnerability allows for possible host environment data extraction
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactCertain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints to unauthorized access. PatchesPatched in v4.4.0 WorkaroundsIf one is unable to update, please make sure that the affected bidder adapters are disabled. References
Updated Aug 18, 2026 · Source: OSV.dev |
v0.274.0
minor
Dependencies (33)
+ 25 more |
|
v0.273.0
minor
1 CVE
CVE-2026-54735
GHSA-4p3g-4hcj-wpvx
GO-2026-6139
Jul 29, 2026
prebid-server's request forgery vulnerability allows for possible host environment data extraction
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactCertain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints to unauthorized access. PatchesPatched in v4.4.0 WorkaroundsIf one is unable to update, please make sure that the affected bidder adapters are disabled. References
Updated Aug 18, 2026 · Source: OSV.dev |
v0.273.0
minor
Dependencies (33)
+ 25 more |
|
v0.272.0
minor
1 CVE
CVE-2026-54735
GHSA-4p3g-4hcj-wpvx
GO-2026-6139
Jul 29, 2026
prebid-server's request forgery vulnerability allows for possible host environment data extraction
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactCertain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints to unauthorized access. PatchesPatched in v4.4.0 WorkaroundsIf one is unable to update, please make sure that the affected bidder adapters are disabled. References
Updated Aug 18, 2026 · Source: OSV.dev |
v0.272.0
minor
Dependencies (33)
+ 25 more |
|
v0.271.0
minor
1 CVE
CVE-2026-54735
GHSA-4p3g-4hcj-wpvx
GO-2026-6139
Jul 29, 2026
prebid-server's request forgery vulnerability allows for possible host environment data extraction
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactCertain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints to unauthorized access. PatchesPatched in v4.4.0 WorkaroundsIf one is unable to update, please make sure that the affected bidder adapters are disabled. References
Updated Aug 18, 2026 · Source: OSV.dev |
v0.271.0
minor
Dependencies (33)
+ 25 more |
|
v0.270.0
minor
1 CVE
CVE-2026-54735
GHSA-4p3g-4hcj-wpvx
GO-2026-6139
Jul 29, 2026
prebid-server's request forgery vulnerability allows for possible host environment data extraction
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactCertain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints to unauthorized access. PatchesPatched in v4.4.0 WorkaroundsIf one is unable to update, please make sure that the affected bidder adapters are disabled. References
Updated Aug 18, 2026 · Source: OSV.dev |
v0.270.0
minor
Dependencies (33)
+ 25 more |
|
v0.269.0
minor
1 CVE
CVE-2026-54735
GHSA-4p3g-4hcj-wpvx
GO-2026-6139
Jul 29, 2026
prebid-server's request forgery vulnerability allows for possible host environment data extraction
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactCertain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints to unauthorized access. PatchesPatched in v4.4.0 WorkaroundsIf one is unable to update, please make sure that the affected bidder adapters are disabled. References
Updated Aug 18, 2026 · Source: OSV.dev |
v0.269.0
minor
Dependencies (33)
+ 25 more |
|
v0.268.0
minor
1 CVE
CVE-2026-54735
GHSA-4p3g-4hcj-wpvx
GO-2026-6139
Jul 29, 2026
prebid-server's request forgery vulnerability allows for possible host environment data extraction
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactCertain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints to unauthorized access. PatchesPatched in v4.4.0 WorkaroundsIf one is unable to update, please make sure that the affected bidder adapters are disabled. References
Updated Aug 18, 2026 · Source: OSV.dev |
v0.268.0
minor
Dependencies (33)
+ 25 more |
|
v0.267.0
minor
1 CVE
CVE-2026-54735
GHSA-4p3g-4hcj-wpvx
GO-2026-6139
Jul 29, 2026
prebid-server's request forgery vulnerability allows for possible host environment data extraction
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactCertain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints to unauthorized access. PatchesPatched in v4.4.0 WorkaroundsIf one is unable to update, please make sure that the affected bidder adapters are disabled. References
Updated Aug 18, 2026 · Source: OSV.dev |
v0.267.0
minor
Dependencies (33)
+ 25 more |
|
v0.266.0
minor
1 CVE
CVE-2026-54735
GHSA-4p3g-4hcj-wpvx
GO-2026-6139
Jul 29, 2026
prebid-server's request forgery vulnerability allows for possible host environment data extraction
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactCertain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints to unauthorized access. PatchesPatched in v4.4.0 WorkaroundsIf one is unable to update, please make sure that the affected bidder adapters are disabled. References
Updated Aug 18, 2026 · Source: OSV.dev |
v0.266.0
minor
Dependencies (33)
+ 25 more |
|
v0.265.0
minor
1 CVE
CVE-2026-54735
GHSA-4p3g-4hcj-wpvx
GO-2026-6139
Jul 29, 2026
prebid-server's request forgery vulnerability allows for possible host environment data extraction
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactCertain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints to unauthorized access. PatchesPatched in v4.4.0 WorkaroundsIf one is unable to update, please make sure that the affected bidder adapters are disabled. References
Updated Aug 18, 2026 · Source: OSV.dev |
v0.265.0
minor
Dependencies (33)
+ 25 more |
|
v0.264.0
minor
1 CVE
CVE-2026-54735
GHSA-4p3g-4hcj-wpvx
GO-2026-6139
Jul 29, 2026
prebid-server's request forgery vulnerability allows for possible host environment data extraction
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactCertain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints to unauthorized access. PatchesPatched in v4.4.0 WorkaroundsIf one is unable to update, please make sure that the affected bidder adapters are disabled. References
Updated Aug 18, 2026 · Source: OSV.dev |
v0.264.0
minor
Dependencies (33)
+ 25 more |
|
v0.263.0
minor
1 CVE
CVE-2026-54735
GHSA-4p3g-4hcj-wpvx
GO-2026-6139
Jul 29, 2026
prebid-server's request forgery vulnerability allows for possible host environment data extraction
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactCertain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints to unauthorized access. PatchesPatched in v4.4.0 WorkaroundsIf one is unable to update, please make sure that the affected bidder adapters are disabled. References
Updated Aug 18, 2026 · Source: OSV.dev |
v0.263.0
minor
Dependencies (33)
+ 25 more |
|
v0.262.1
patch
1 CVE
CVE-2026-54735
GHSA-4p3g-4hcj-wpvx
GO-2026-6139
Jul 29, 2026
prebid-server's request forgery vulnerability allows for possible host environment data extraction
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactCertain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints to unauthorized access. PatchesPatched in v4.4.0 WorkaroundsIf one is unable to update, please make sure that the affected bidder adapters are disabled. References
Updated Aug 18, 2026 · Source: OSV.dev |
v0.262.1
patch
Dependencies (33)
+ 25 more |
|
v0.262.0
minor
1 CVE
CVE-2026-54735
GHSA-4p3g-4hcj-wpvx
GO-2026-6139
Jul 29, 2026
prebid-server's request forgery vulnerability allows for possible host environment data extraction
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactCertain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints to unauthorized access. PatchesPatched in v4.4.0 WorkaroundsIf one is unable to update, please make sure that the affected bidder adapters are disabled. References
Updated Aug 18, 2026 · Source: OSV.dev |
v0.262.0
minor
Dependencies (33)
+ 25 more |
|
v0.261.0
minor
1 CVE
CVE-2026-54735
GHSA-4p3g-4hcj-wpvx
GO-2026-6139
Jul 29, 2026
prebid-server's request forgery vulnerability allows for possible host environment data extraction
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactCertain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints to unauthorized access. PatchesPatched in v4.4.0 WorkaroundsIf one is unable to update, please make sure that the affected bidder adapters are disabled. References
Updated Aug 18, 2026 · Source: OSV.dev |
v0.261.0
minor
Dependencies (33)
+ 25 more |
|
v0.260.0
minor
1 CVE
CVE-2026-54735
GHSA-4p3g-4hcj-wpvx
GO-2026-6139
Jul 29, 2026
prebid-server's request forgery vulnerability allows for possible host environment data extraction
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactCertain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints to unauthorized access. PatchesPatched in v4.4.0 WorkaroundsIf one is unable to update, please make sure that the affected bidder adapters are disabled. References
Updated Aug 18, 2026 · Source: OSV.dev |
v0.260.0
minor
Dependencies (33)
+ 25 more |
|
v0.259.0
minor
1 CVE
CVE-2026-54735
GHSA-4p3g-4hcj-wpvx
GO-2026-6139
Jul 29, 2026
prebid-server's request forgery vulnerability allows for possible host environment data extraction
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactCertain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints to unauthorized access. PatchesPatched in v4.4.0 WorkaroundsIf one is unable to update, please make sure that the affected bidder adapters are disabled. References
Updated Aug 18, 2026 · Source: OSV.dev |
v0.259.0
minor
Dependencies (33)
+ 25 more |
|
v0.258.0
minor
1 CVE
CVE-2026-54735
GHSA-4p3g-4hcj-wpvx
GO-2026-6139
Jul 29, 2026
prebid-server's request forgery vulnerability allows for possible host environment data extraction
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactCertain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints to unauthorized access. PatchesPatched in v4.4.0 WorkaroundsIf one is unable to update, please make sure that the affected bidder adapters are disabled. References
Updated Aug 18, 2026 · Source: OSV.dev |
v0.258.0
minor
Dependencies (33)
+ 25 more |
|
v0.257.0
initial
1 CVE
CVE-2026-54735
GHSA-4p3g-4hcj-wpvx
GO-2026-6139
Jul 29, 2026
prebid-server's request forgery vulnerability allows for possible host environment data extraction
10.0
/ 10
Critical
Network
Low
None
None
Changed
High
High
High
ImpactCertain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints to unauthorized access. PatchesPatched in v4.4.0 WorkaroundsIf one is unable to update, please make sure that the affected bidder adapters are disabled. References
Updated Aug 18, 2026 · Source: OSV.dev |
v0.257.0
initial
Dependencies (33)
+ 25 more |