Back to blog

// OSSeva Blog

Security

Apache Druid Vulnerabilities by Version: CVEs for Druid 0.x and 24 to 38

Matt Reynolds8 min read

The short answer

Apache Druid has no long-term support line and no published end-of-life dates. The download page offers two releases, 38.0.0 from 1 October 2026 and 37.0.0 from 8 May 2026, and points to the Apache archive for everything else. Fixes land in the next release, with an occasional patch release on the line before it, so a cluster stays covered only by moving forward through the major versions.

The two most serious Druid CVEs of the last year are both authentication bypasses scored 9.8 by CISA-ADP. CVE-2026-23906 lets anyone log in with an existing username and an empty password when the LDAP server allows anonymous bind, and it is fixed only from 36.0.0. CVE-2025-59390 lets an attacker forge Kerberos authentication cookies when no signing secret is configured, and it is fixed from 35.0.0. Every release from 0.17.0 to 34.0.0 carries both.

Druid release lines and their CVEs

Release dates are from the apache/druid GitHub releases and the Druid download page. Each row lists the CVEs from the Apache advisories for Druid whose ranges include the line and that have no fix in its latest release; each row also carries the CVEs of the rows above it.

LineUpstream statusLatest releaseCVEs with no fix on this lineUpstream fix on this line
38Latest release on the download page38.0.0, 1 October 2026NoneNot applicable
37Previous release on the download page37.0.0, 8 May 2026NoneNot applicable
36Archived; no further releases36.0.0, 9 February 2026None36.0.0 for CVE-2026-23906
35Archived35.0.1, 15 December 2025CVE-2026-2390635.0.0 for CVE-2025-59390
31 to 34Archived34.0.0, 11 August 2025; 33.0.0; 32.0.1 and 31.0.2, 19 March 2025CVE-2025-5939031.0.2 and 32.0.1 for CVE-2025-27888
30Archived30.0.1, 17 September 2024CVE-2025-2788830.0.1 for CVE-2024-45537 and CVE-2024-45384
24 to 29, and 0.23Archived29.0.1, 3 April 2024; 24.0.2, 22 December 2022; 0.23.0CVE-2024-45537, CVE-2024-45384No upstream fix on these lines
0.22Archived0.22.1, 11 December 2021CVE-2021-44791, CVE-2022-288890.22.0 for CVE-2021-26920 and CVE-2021-36749
0.17 to 0.21Archived0.21.1, 10 June 2021; 0.20.2CVE-2021-26920 and CVE-2021-36749; CVE-2021-26919 before 0.20.2; CVE-2021-25646 on 0.20.0 and older0.20.2 for CVE-2021-26919; 0.20.1 for CVE-2021-25646

Druid moved from 0.23.0 to 24.0.0 in September 2022, dropping the leading zero, so 24 follows 0.23 directly. The 31.0.0 and 31.0.1 releases and 32.0.0 also lack the CVE-2025-27888 fix, which came in 31.0.2 and 32.0.1. For release dates on every line, see the Apache Druid release history and end-of-life chart.

Notable Druid CVEs by release line

CVSS is NVD's own score where NVD has scored the record, otherwise the CVSS 3.1 score CISA-ADP added. Apache, as the CNA, scores CVE-2025-27888 at 5.8 under CVSS 4.0. None of these CVEs is in CISA's Known Exploited Vulnerabilities catalogue.

CVEIssueCVSSAffectedFixed in
CVE-2026-23906With druid-basic-security and an LDAP authenticator, an existing username with an empty password logs in when the LDAP server permits anonymous bind9.8 (CISA-ADP)0.17.0 to 35.x36.0.0
CVE-2025-59390Without druid.auth.authenticator.kerberos.cookieSignatureSecret set, the Kerberos authenticator signs cookies with a weak, per-process random secret that can be predicted or brute forced9.8 (CISA-ADP)Through 34.0.035.0.0, which makes the secret mandatory
CVE-2021-25646An authenticated user can force Druid to run user-supplied JavaScript even when JavaScript is disabled, running code as the Druid process8.8 (NVD)0.20.0 and earlier0.20.1
CVE-2021-26919MySQL JDBC properties in lookups or ingestion let an authenticated user run code from a malicious MySQL server8.8 (NVD)Through 0.20.10.20.2
CVE-2024-45537A crafted MySQL JDBC connection string sets properties outside the configured allow list, a gap left by the CVE-2021-26919 fix6.5 (NVD)Through 30.0.030.0.1
CVE-2021-36749The HTTP input source lets authenticated users read local files, an incomplete fix of CVE-2021-269206.5 (NVD)Through 0.21.10.22.0
CVE-2021-44791Crafted links return unescaped URL parameters in HTML responses, a reflected cross-site scripting flaw6.1 (NVD)0.22.1 and earlier0.23.0
CVE-2025-27888A crafted URL through the management proxy, on by default, redirects requests to another server, allowing SSRF, XSS or XSRF by an authenticated user5.4 (NVD)Before 31.0.2; 32.0.031.0.2, 32.0.1
CVE-2024-45384A padding oracle in the optional druid-pac4j extension lets an attacker manipulate session cookies5.3 (NVD)0.18.0 to 30.0.030.0.1

Most of the list depends on which extensions and features a cluster uses. CVE-2026-23906 needs druid-basic-security with an LDAP authenticator, CVE-2025-59390 needs the Kerberos authenticator, and CVE-2024-45384 needs druid-pac4j. The JDBC CVEs need a user who is allowed to define lookups or ingestion tasks with JDBC. CVE-2025-27888 is different because the management proxy is on in Druid's default configuration, and turning it off disables some web console features.

Druid also depends on ZooKeeper for leader election and cluster state. Druid 0.22.1 and 25.0.0 bundle ZooKeeper 3.5.9, from a line that reached end of life in June 2022. Releases from 30.0.0 to 36.0.0 bundle 3.8.4, and 37.0.0 and 38.0.0 bundle 3.8.6, all inside the range of the ZooKeeper advisories published in September 2026, which are fixed in 3.8.7.

What each line gets

Druid 37 and 38

These are the two releases on the download page and both carry every Druid fix above. No Druid release yet bundles ZooKeeper 3.8.7, so the September 2026 ZooKeeper fixes need a patched ensemble or a later Druid release.

Druid 35 and 36

36.0.0 has every Druid fix above. 35.0.1 lacks the LDAP anonymous bind fix, which matters only with an LDAP authenticator; disabling anonymous bind on the LDAP server closes it without a Druid upgrade.

Druid 30 to 34

These lack the Kerberos cookie fix and, on 30, the management proxy fix. The CVE-2025-59390 advisory's workaround is to set a strong druid.auth.authenticator.kerberos.cookieSignatureSecret, which every cluster using the Kerberos authenticator can do without upgrading.

Druid 24 to 29 and 0.23

These also lack the 30.0.1 fixes for MySQL JDBC properties and druid-pac4j. 25.0 moved segment discovery and task management from ZooKeeper to HTTP by default, and 30.0 removed ZooKeeper-based segment loading, so the upgrade from here needs a careful read of each set of release notes.

Druid 0.22 and older

0.22.1 adds the reflected XSS and clickjacking CVEs fixed in 0.23.0. Releases up to 0.20.0 also carry CVE-2021-25646, the JavaScript execution flaw, and up to 0.20.1 the MySQL JDBC code execution flaw, CVE-2021-26919.

What to do on each line

  • 37 and 38. Stay on 38.0.0 or 37.0.0 and plan to take the next release, since older ones stop getting fixes once they leave the download page.
  • 30 to 36. Move to 38.0.0. Until then, disable anonymous bind on the LDAP server, set the Kerberos cookie signature secret explicitly, and turn off the management proxy if you can do without the console features that use it.
  • 29 and older. Plan the upgrade across each major version, or take patched builds from a supplier that backports fixes. Until then, apply the same steps, restrict who can define JDBC lookups and ingestion tasks, keep JavaScript disabled, and keep Druid's HTTP ports off untrusted networks.

For the support and upgrade options beyond security, see Apache Druid support options.

Where OSSeva fits

OSSeva ships patched, signed builds for archived Apache Druid releases, including 0.22, 25 and 30 to 36, with security backports on the release you run, segments untouched, the bundled ZooKeeper and Curator patched in the same build, and extension and transitive dependency patching for Jetty, Jackson and Netty, delivered as Docker images and tarballs with VEX statements for scanner findings. OSSeva backports fixes of this class to the end-of-life release lines it patches. They are available now on the Patch, Assure and Operate tiers. Assure adds a Coordinator, Overlord and ZooKeeper quorum review, an authentication, authorisation and JavaScript setting audit, an extension inventory and an upgrade plan across every major version between you and 38, and Operate adds 24/7 query latency, ingestion lag and segment load monitoring with a 15-minute P1 response and a named senior Druid engineer. See Apache Druid support and Apache Druid support plans.

Tags

Apache DruidCVEDruid 38Druid 0.22End of Life

Ready to get your open source under control?

Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.