VendorsApachedruidany version
Vulnerabilities

Apache Software Foundation Druid any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

11CVEs
CVE-2026-23906
Apache Druid: Authentication Bypass via LDAP Anonymous Bind
Published 2026-02-10 · Modified
9.8EPSS 0.011
CVE-2025-59390
Apache Druid: Kerberos authenticaton chooses a cryptographically unsecure secret if not configured explicitly.
Published 2025-11-26 · Analyzed
9.8EPSS 0.006
CVE-2021-25646
Authenticated users can override system configurations in their requests which allows them to execute arbitrary code.
Published 2021-01-29 · Modified
9.0EPSS 0.990
CVE-2021-26919
Apache Druid Authenticated users can execute arbitrary code from malicious MySQL database systems.
Published 2021-03-30 · Modified
8.8EPSS 0.228
CVE-2021-36749
Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended (incomplete fix of CVE-2021-26920)
Published 2021-09-24 · Modified
6.5EPSS 0.809
CVE-2021-26920
Apache Druid: The HTTP inputSource allows authenticated users to read data from other sources than intended
Published 2021-07-02 · Modified
6.5EPSS 0.095
CVE-2024-45537
Apache Druid: Users can provide MySQL JDBC properties not on allow list
Published 2024-09-17 · Modified
6.5EPSS 0.006
CVE-2021-44791
Reflected XSS on certain HTTP endpoints
Published 2022-07-07 · Modified
6.1EPSS 0.022
CVE-2025-27888
Apache Druid: Server-Side Request Forgery and Cross-Site Scripting
Published 2025-03-20 · Analyzed
5.8EPSS 0.018
CVE-2024-45384
Apache Druid: Padding oracle in druid-pac4j extension that allows an attacker to manipulate a pac4j session cookie via Padding Oracle Attack
Published 2024-09-17 · Modified
5.3EPSS 0.008
CVE-2022-28889
Clickjacking in the web console
Published 2022-07-07 · Modified
4.3EPSS 0.019