// OSSeva Blog
SecurityApache Druid Vulnerabilities by Version: CVEs for Druid 0.x and 24 to 38
The short answer
Apache Druid has no long-term support line and no published end-of-life dates. The download page offers two releases, 38.0.0 from 1 October 2026 and 37.0.0 from 8 May 2026, and points to the Apache archive for everything else. Fixes land in the next release, with an occasional patch release on the line before it, so a cluster stays covered only by moving forward through the major versions.
The two most serious Druid CVEs of the last year are both authentication bypasses scored 9.8 by CISA-ADP. CVE-2026-23906 lets anyone log in with an existing username and an empty password when the LDAP server allows anonymous bind, and it is fixed only from 36.0.0. CVE-2025-59390 lets an attacker forge Kerberos authentication cookies when no signing secret is configured, and it is fixed from 35.0.0. Every release from 0.17.0 to 34.0.0 carries both.
Druid release lines and their CVEs
Release dates are from the apache/druid GitHub releases and the Druid download page. Each row lists the CVEs from the Apache advisories for Druid whose ranges include the line and that have no fix in its latest release; each row also carries the CVEs of the rows above it.
| Line | Upstream status | Latest release | CVEs with no fix on this line | Upstream fix on this line |
|---|---|---|---|---|
| 38 | Latest release on the download page | 38.0.0, 1 October 2026 | None | Not applicable |
| 37 | Previous release on the download page | 37.0.0, 8 May 2026 | None | Not applicable |
| 36 | Archived; no further releases | 36.0.0, 9 February 2026 | None | 36.0.0 for CVE-2026-23906 |
| 35 | Archived | 35.0.1, 15 December 2025 | CVE-2026-23906 | 35.0.0 for CVE-2025-59390 |
| 31 to 34 | Archived | 34.0.0, 11 August 2025; 33.0.0; 32.0.1 and 31.0.2, 19 March 2025 | CVE-2025-59390 | 31.0.2 and 32.0.1 for CVE-2025-27888 |
| 30 | Archived | 30.0.1, 17 September 2024 | CVE-2025-27888 | 30.0.1 for CVE-2024-45537 and CVE-2024-45384 |
| 24 to 29, and 0.23 | Archived | 29.0.1, 3 April 2024; 24.0.2, 22 December 2022; 0.23.0 | CVE-2024-45537, CVE-2024-45384 | No upstream fix on these lines |
| 0.22 | Archived | 0.22.1, 11 December 2021 | CVE-2021-44791, CVE-2022-28889 | 0.22.0 for CVE-2021-26920 and CVE-2021-36749 |
| 0.17 to 0.21 | Archived | 0.21.1, 10 June 2021; 0.20.2 | CVE-2021-26920 and CVE-2021-36749; CVE-2021-26919 before 0.20.2; CVE-2021-25646 on 0.20.0 and older | 0.20.2 for CVE-2021-26919; 0.20.1 for CVE-2021-25646 |
Druid moved from 0.23.0 to 24.0.0 in September 2022, dropping the leading zero, so 24 follows 0.23 directly. The 31.0.0 and 31.0.1 releases and 32.0.0 also lack the CVE-2025-27888 fix, which came in 31.0.2 and 32.0.1. For release dates on every line, see the Apache Druid release history and end-of-life chart.
Notable Druid CVEs by release line
CVSS is NVD's own score where NVD has scored the record, otherwise the CVSS 3.1 score CISA-ADP added. Apache, as the CNA, scores CVE-2025-27888 at 5.8 under CVSS 4.0. None of these CVEs is in CISA's Known Exploited Vulnerabilities catalogue.
| CVE | Issue | CVSS | Affected | Fixed in |
|---|---|---|---|---|
| CVE-2026-23906 | With druid-basic-security and an LDAP authenticator, an existing username with an empty password logs in when the LDAP server permits anonymous bind | 9.8 (CISA-ADP) | 0.17.0 to 35.x | 36.0.0 |
| CVE-2025-59390 | Without druid.auth.authenticator.kerberos.cookieSignatureSecret set, the Kerberos authenticator signs cookies with a weak, per-process random secret that can be predicted or brute forced | 9.8 (CISA-ADP) | Through 34.0.0 | 35.0.0, which makes the secret mandatory |
| CVE-2021-25646 | An authenticated user can force Druid to run user-supplied JavaScript even when JavaScript is disabled, running code as the Druid process | 8.8 (NVD) | 0.20.0 and earlier | 0.20.1 |
| CVE-2021-26919 | MySQL JDBC properties in lookups or ingestion let an authenticated user run code from a malicious MySQL server | 8.8 (NVD) | Through 0.20.1 | 0.20.2 |
| CVE-2024-45537 | A crafted MySQL JDBC connection string sets properties outside the configured allow list, a gap left by the CVE-2021-26919 fix | 6.5 (NVD) | Through 30.0.0 | 30.0.1 |
| CVE-2021-36749 | The HTTP input source lets authenticated users read local files, an incomplete fix of CVE-2021-26920 | 6.5 (NVD) | Through 0.21.1 | 0.22.0 |
| CVE-2021-44791 | Crafted links return unescaped URL parameters in HTML responses, a reflected cross-site scripting flaw | 6.1 (NVD) | 0.22.1 and earlier | 0.23.0 |
| CVE-2025-27888 | A crafted URL through the management proxy, on by default, redirects requests to another server, allowing SSRF, XSS or XSRF by an authenticated user | 5.4 (NVD) | Before 31.0.2; 32.0.0 | 31.0.2, 32.0.1 |
| CVE-2024-45384 | A padding oracle in the optional druid-pac4j extension lets an attacker manipulate session cookies | 5.3 (NVD) | 0.18.0 to 30.0.0 | 30.0.1 |
Most of the list depends on which extensions and features a cluster uses. CVE-2026-23906 needs druid-basic-security with an LDAP authenticator, CVE-2025-59390 needs the Kerberos authenticator, and CVE-2024-45384 needs druid-pac4j. The JDBC CVEs need a user who is allowed to define lookups or ingestion tasks with JDBC. CVE-2025-27888 is different because the management proxy is on in Druid's default configuration, and turning it off disables some web console features.
Druid also depends on ZooKeeper for leader election and cluster state. Druid 0.22.1 and 25.0.0 bundle ZooKeeper 3.5.9, from a line that reached end of life in June 2022. Releases from 30.0.0 to 36.0.0 bundle 3.8.4, and 37.0.0 and 38.0.0 bundle 3.8.6, all inside the range of the ZooKeeper advisories published in September 2026, which are fixed in 3.8.7.
What each line gets
Druid 37 and 38
These are the two releases on the download page and both carry every Druid fix above. No Druid release yet bundles ZooKeeper 3.8.7, so the September 2026 ZooKeeper fixes need a patched ensemble or a later Druid release.
Druid 35 and 36
36.0.0 has every Druid fix above. 35.0.1 lacks the LDAP anonymous bind fix, which matters only with an LDAP authenticator; disabling anonymous bind on the LDAP server closes it without a Druid upgrade.
Druid 30 to 34
These lack the Kerberos cookie fix and, on 30, the management proxy fix. The CVE-2025-59390 advisory's workaround is to set a strong druid.auth.authenticator.kerberos.cookieSignatureSecret, which every cluster using the Kerberos authenticator can do without upgrading.
Druid 24 to 29 and 0.23
These also lack the 30.0.1 fixes for MySQL JDBC properties and druid-pac4j. 25.0 moved segment discovery and task management from ZooKeeper to HTTP by default, and 30.0 removed ZooKeeper-based segment loading, so the upgrade from here needs a careful read of each set of release notes.
Druid 0.22 and older
0.22.1 adds the reflected XSS and clickjacking CVEs fixed in 0.23.0. Releases up to 0.20.0 also carry CVE-2021-25646, the JavaScript execution flaw, and up to 0.20.1 the MySQL JDBC code execution flaw, CVE-2021-26919.
What to do on each line
- 37 and 38. Stay on 38.0.0 or 37.0.0 and plan to take the next release, since older ones stop getting fixes once they leave the download page.
- 30 to 36. Move to 38.0.0. Until then, disable anonymous bind on the LDAP server, set the Kerberos cookie signature secret explicitly, and turn off the management proxy if you can do without the console features that use it.
- 29 and older. Plan the upgrade across each major version, or take patched builds from a supplier that backports fixes. Until then, apply the same steps, restrict who can define JDBC lookups and ingestion tasks, keep JavaScript disabled, and keep Druid's HTTP ports off untrusted networks.
For the support and upgrade options beyond security, see Apache Druid support options.
Where OSSeva fits
OSSeva ships patched, signed builds for archived Apache Druid releases, including 0.22, 25 and 30 to 36, with security backports on the release you run, segments untouched, the bundled ZooKeeper and Curator patched in the same build, and extension and transitive dependency patching for Jetty, Jackson and Netty, delivered as Docker images and tarballs with VEX statements for scanner findings. OSSeva backports fixes of this class to the end-of-life release lines it patches. They are available now on the Patch, Assure and Operate tiers. Assure adds a Coordinator, Overlord and ZooKeeper quorum review, an authentication, authorisation and JavaScript setting audit, an extension inventory and an upgrade plan across every major version between you and 38, and Operate adds 24/7 query latency, ingestion lag and segment load monitoring with a 15-minute P1 response and a named senior Druid engineer. See Apache Druid support and Apache Druid support plans.
Tags
Related articles
Apache Storm Vulnerabilities by Version: CVEs for Storm 1.2, 2.x and 3.x
October 6, 2026Securityetcd Vulnerabilities by Version: CVEs for etcd 3.3, 3.4, 3.5, 3.6 and 3.7
October 6, 2026SecurityClickHouse Vulnerabilities by Version: CVEs for ClickHouse 22.x to 26.x, LTS and Stable
October 6, 2026Ready to get your open source under control?
Talk to an OSSeva engineer about CVE coverage, compliance, and migration support for your stack.