Apache Software Foundation Apache Druid vulnerabilities
9 known vulnerabilities affecting apache_software_foundation/apache_druid.
Total CVEs
9
CISA KEV
0
Public exploits
3
Exploited in wild
2
Severity breakdown
CRITICAL2HIGH2MEDIUM5
Vulnerabilities
Page 1 of 1
CVE-2021-25646P1HIGHCVSS 8.8ExploitedPoC≥ 0.20.0 and earlier, ≤ 0.20.02021-01-29
CVE-2021-25646 [HIGH] CVE-2021-25646: Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types
Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However, in Druid 0.20.0 and earlier, it is possible for an authenticated user to send a specially-crafted request that forces Druid to run user-provide
nvd
CVE-2021-26920P2MEDIUMCVSS 6.5ExploitedPoC≥ 0.21.1 and earlier, ≤ 0.21.12021-07-02
CVE-2021-26920 [MEDIUM] CWE-610 CVE-2021-26920: In the Druid ingestion system, the InputSource is used for reading data from a certain data source.
In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from other sources than intended, such as the local file system, with the privileges of the Druid server process. This is not an elevation of privilege when users access Druid direct
nvd
CVE-2021-26919P2HIGHCVSS 8.8≤ 30.0.02021-03-30
CVE-2021-26919 [HIGH] CWE-20 CVE-2021-26919: Apache Druid allows users to read data from other database systems using JDBC. This functionality is
Apache Druid allows users to read data from other database systems using JDBC. This functionality is to allow trusted users with the proper permissions to set up lookups or submit ingestion tasks. The MySQL JDBC driver supports certain properties, which, if left unmitigated, can allow an attacker to execute arbitrary code from a hacker-controlled malic
nvd
CVE-2026-23906P2CRITICALCVSS 9.8≥ 0.17.0, < 36.0.02026-02-10
CVE-2026-23906 [CRITICAL] CWE-287 CVE-2026-23906: Affected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all ve
Affected Products and Versions
* Apache Druid
* Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0)
* Prerequisites: * druid-basic-security extension enabled
* LDAP authenticator configured
* Underlying LDAP server permits anonymous bind
Vulnerability Description
An authentication bypass vulnerability exists in Apache Druid when usi
nvd
CVE-2025-59390P2CRITICALCVSS 9.8≤ 34.0.02025-11-26
CVE-2025-59390 [CRITICAL] CWE-338 CVE-2025-59390: Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator
Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSignatureSecret` configuration is not explicitly set. In this case, the secret is generated using `ThreadLocalRandom`,
which is not a crypto-graphically secure random number generator. This
may allow an attacker to predict or brute f
nvd
CVE-2025-27888P3MEDIUMCVSS 5.4PoCfixed in 31.0.2v32.0.02025-03-20
CVE-2025-27888 [MEDIUM] CWE-79 CVE-2025-27888: Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of I
Severity: medium (5.8) / important
Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache Druid.
This issue affects all previous Druid versions.
When using the Druid management proxy, a request that has a s
nvd
CVE-2024-45384P4MEDIUMCVSS 5.3≥ 0.18.0, ≤ 30.0.02024-09-17
CVE-2024-45384 [MEDIUM] CWE-209 CVE-2024-45384: Padding Oracle vulnerability in Apache Druid extension, druid-pac4j. This could allow an attacker to
Padding Oracle vulnerability in Apache Druid extension, druid-pac4j.
This could allow an attacker to manipulate a pac4j session cookie.
This issue affects Apache Druid versions 0.18.0 through 30.0.0.
Since the druid-pac4j extension is optional and disabled by default, Druid installations not using the druid-pac4j extension are not affected by this
nvd
CVE-2021-44791P4MEDIUMCVSS 6.1≥ Apache Druid, ≤ 0.22.12022-07-07
CVE-2021-44791 [MEDIUM] CWE-79 CVE-2021-44791: In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL paramete
In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back in HTML responses. This makes it possible to execute reflected XSS attacks.
nvd
CVE-2022-28889P4MEDIUMCVSS 4.3≥ unspecified, ≤ 0.22.12022-07-07
CVE-2022-28889 [MEDIUM] CWE-1021 CVE-2022-28889: In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacki
In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking. Druid 0.23.0 and later prevent clickjacking using the Content-Security-Policy header.
nvd