VendorsApachedruidall versions
Vulnerabilities

Apache Software Foundation Druid

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

12CVEs
CVE-2026-23906
Apache Druid: Authentication Bypass via LDAP Anonymous Bind
Published 2026-02-10 · Modified
9.8EPSS 0.011
CVE-2025-59390
Apache Druid: Kerberos authenticaton chooses a cryptographically unsecure secret if not configured explicitly.
Published 2025-11-26 · Analyzed
9.8EPSS 0.006
CVE-2021-25646
Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.
Published 2021-01-29 · Modified
9.0EPSS 0.990
CVE-2021-26919
Apache Druid Authenticated users can execute arbitrary code from malicious MySQL database systems.
Published 2021-03-30 · Modified
8.8EPSS 0.228
CVE-2021-36749
Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended (incomplete fix of CVE-2021-26920)
Published 2021-09-24 · Modified
6.5EPSS 0.809
CVE-2021-26920
Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended
Published 2021-07-02 · Modified
6.5EPSS 0.095
CVE-2020-1958
When LDAP authentication is enabled in Apache Druid 0.17.0, callers of Druid APIs with a valid set of LDAP credentials can bypass the credentialsValidator.userSearch filter barrier that determines if a valid LDAP user is allowed to authenticate with Druid. They are still subject to role-based authorization checks, if configured. Callers of Druid APIs can also retrieve any LDAP attribute values of users that exist on the LDAP server, so long as that information is visible to the Druid server. This information disclosure does not require the caller itself to be a valid LDAP user.
Published 2020-04-01 · Modified
6.5EPSS 0.046
CVE-2024-45537
Apache Druid: Users can provide MySQL JDBC properties not on allow list
Published 2024-09-17 · Modified
6.5EPSS 0.006
CVE-2021-44791
Reflected XSS on certain HTTP endpoints
Published 2022-07-07 · Modified
6.1EPSS 0.022
CVE-2025-27888
Apache Druid: Server-Side Request Forgery and Cross-Site Scripting
Published 2025-03-20 · Analyzed
5.8EPSS 0.018
CVE-2024-45384
Apache Druid: Padding oracle in druid-pac4j extension that allows an attacker to manipulate a pac4j session cookie via Padding Oracle Attack
Published 2024-09-17 · Modified
5.3EPSS 0.008
CVE-2022-28889
Clickjacking in the web console
Published 2022-07-07 · Modified
4.3EPSS 0.019