See how prebid.org compares to other vendors in security performance
Impact Certain bidder adapters accept user-supplied parameters that are interpolated into outbound request URLs. Without proper input validation, a malicious actor could craft bid request parameters that cause the server to send HTTP requests to unintended destinations, potentially exposing internal network services or sensitive server endpoints to unauthorized access.
Patches Patched in v4.4.0
Workarounds If one is unable to update, please make sure that the affected bidder adapters are disabled.