Skip to main content

Vendor/product archive

apache / druid CVEs

Beta · best-effort

12 CVEs tagged to apache / druid2 Critical, 2 High, 8 Medium, 0 Low, 0 Unrated.

CVE-2026-23906

Published Feb 10, 2026

Affected Products and Versions * Apache Druid * Affected Versions: 0.17.0 through 35.x (all versions prior to 36.0.0) * Prerequisites: * druid-basic-security extension…

CVSS 9.8 · Critical
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2025-59390

Published Nov 26, 2025

Apache Druid’s Kerberos authenticator uses a weak fallback secret when the `druid.auth.authenticator.kerberos.cookieSignatureSecret` configuration is not explicitly set. In this c…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2025-27888

Published Mar 20, 2025

Severity: medium (5.8) / important Server-Side Request Forgery (SSRF), Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), URL Redirection to Un…

CVSS 5.8 · Medium
evidence mentions
2
Buzz score
21.0
Vendor/product tagsBeta · best-effort

CVE-2024-45537

Published Sep 17, 2024

Apache Druid allows users with certain permissions to read data from other database systems using JDBC. This functionality allows trusted users to set up Druid lookups or run inge…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2024-45384

Published Sep 17, 2024

Padding Oracle vulnerability in Apache Druid extension, druid-pac4j. This could allow an attacker to manipulate a pac4j session cookie. This issue affects Apache Druid versions 0…

CVSS 5.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2022-28889

Published Jul 7, 2022

In Apache Druid 0.22.1 and earlier, the server did not set appropriate headers to prevent clickjacking. Druid 0.23.0 and later prevent clickjacking using the Content-Security-Poli…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-44791

Published Jul 7, 2022

In Apache Druid 0.22.1 and earlier, certain specially-crafted links result in unescaped URL parameters being sent back in HTML responses. This makes it possible to execute reflect…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-36749

Published Sep 24, 2021

In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from othe…

CVSS 6.5 · Medium
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2021-26920

Published Jul 2, 2021

In the Druid ingestion system, the InputSource is used for reading data from a certain data source. However, the HTTP InputSource allows authenticated users to read data from othe…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort

CVE-2021-26919

Published Mar 30, 2021

Apache Druid allows users to read data from other database systems using JDBC. This functionality is to allow trusted users with the proper permissions to set up lookups or submit…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2021-25646

Published Jan 29, 2021

Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2020-1958

Published Apr 1, 2020

When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsValidator.userSearch filter barrie…

CVSS 6.5 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-12 of 12 CVEsPage 1 of 1