CVE Tools

Druid

13 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Druid, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Druid CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Druid CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-031
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-111
2025-120
2026-010
2026-021
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-090

Severity

How the 13 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical215%
  • High323%
  • Medium862%

Latest CVEs

The 13 most recently published vulnerabilities affecting Druid.

  1. CVE-2026-23906Apache Druid: Authentication Bypass via LDAP Anonymous Bind9.8
  2. CVE-2025-59390Apache Druid: Kerberos authenticaton chooses a cryptographically unsecure secret if not configured explicitly.9.8
  3. CVE-2025-27888Apache Druid: Server-Side Request Forgery and Cross-Site Scripting5.4
  4. CVE-2024-45537Apache Druid: Users can provide MySQL JDBC properties not on allow list6.5
  5. CVE-2024-45384Apache Druid: Padding oracle in druid-pac4j extension that allows an attacker to manipulate a pac4j session cookie via Padding Oracle Attack5.3
  6. CVE-2022-28889Clickjacking in the web console4.3
  7. CVE-2021-44791Reflected XSS on certain HTTP endpoints6.1
  8. CVE-2021-33800In Druid 1.2.3, visiting the path with parameter in a certain function can lead to directory traversal.7.5
  9. CVE-2021-36749Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended (incomplete fix of CVE-2021-26920)6.5
  10. CVE-2021-26920Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended6.5
  11. CVE-2021-26919Apache Druid Authenticated users can execute arbitrary code from malicious MySQL database systems.8.8
  12. CVE-2021-25646Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.8.8
  13. CVE-2020-1958When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsValidator.userSearch filter barrier that determines ...6.5

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store