CVE Tools

Apache Druid

12 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Apache Druid, a product in the databases space. Use it to gauge the current risk picture and drill into individual advisories.

Apache Druid CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Apache Druid CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-031
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-111
2025-120
2026-010
2026-021
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 12 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical217%
  • High217%
  • Medium867%

Latest CVEs

The 12 most recently published vulnerabilities affecting Apache Druid.

  1. CVE-2026-23906Apache Druid: Authentication Bypass via LDAP Anonymous Bind9.8
  2. CVE-2025-59390Apache Druid: Kerberos authenticaton chooses a cryptographically unsecure secret if not configured explicitly.9.8
  3. CVE-2025-27888Apache Druid: Server-Side Request Forgery and Cross-Site Scripting5.4
  4. CVE-2024-45537Apache Druid: Users can provide MySQL JDBC properties not on allow list6.5
  5. CVE-2024-45384Apache Druid: Padding oracle in druid-pac4j extension that allows an attacker to manipulate a pac4j session cookie via Padding Oracle Attack5.3
  6. CVE-2022-28889Clickjacking in the web console4.3
  7. CVE-2021-44791Reflected XSS on certain HTTP endpoints6.1
  8. CVE-2021-36749Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended (incomplete fix of CVE-2021-26920)6.5
  9. CVE-2021-26920Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended6.5
  10. CVE-2021-26919Apache Druid Authenticated users can execute arbitrary code from malicious MySQL database systems.8.8
  11. CVE-2021-25646Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.8.8
  12. CVE-2020-1958When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsValidator.userSearch filter barrier that determines ...6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store