CVE Tools

Apache Druid

12 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Apache Druid, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Apache Druid CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Apache Druid CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-031
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-111
2025-120
2026-010
2026-021
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 12 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical217%
  • High217%
  • Medium867%

Latest CVEs

The 12 most recently published vulnerabilities affecting Apache Druid.

  1. CVE-2026-23906Apache Druid: Authentication Bypass via LDAP Anonymous Bind9.8
  2. CVE-2025-59390Apache Druid: Kerberos authenticaton chooses a cryptographically unsecure secret if not configured explicitly.9.8
  3. CVE-2025-27888Apache Druid: Server-Side Request Forgery and Cross-Site Scripting5.4
  4. CVE-2024-45537Apache Druid: Users can provide MySQL JDBC properties not on allow list6.5
  5. CVE-2024-45384Apache Druid: Padding oracle in druid-pac4j extension that allows an attacker to manipulate a pac4j session cookie via Padding Oracle Attack5.3
  6. CVE-2022-28889Clickjacking in the web console4.3
  7. CVE-2021-44791Reflected XSS on certain HTTP endpoints6.1
  8. CVE-2021-36749Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended (incomplete fix of CVE-2021-26920)6.5
  9. CVE-2021-26920Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended6.5
  10. CVE-2021-26919Apache Druid Authenticated users can execute arbitrary code from malicious MySQL database systems.8.8
  11. CVE-2021-25646Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.8.8
  12. CVE-2020-1958When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsValidator.userSearch filter barrier that determines ...6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store