Back to Vulnerability Directory
CRITICALFixed upstream

CVE-2025-59390

Apache Druid: Kerberos authenticator falls back to a weak cookie signing secret

Technology

Apache Druid

CVSS Score

9.8 / 10.0

Affected Versions

Apache Druid through 34.0.0, with the Kerberos authenticator

Upstream Fix

35.0.0

Published

November 26, 2025

OSSeva Coverage

Fixed upstream

Description

If druid.auth.authenticator.kerberos.cookieSignatureSecret is not set, the Kerberos authenticator generates a signing secret with ThreadLocalRandom, which is not cryptographically secure, so an attacker may predict or brute force it and forge authentication cookies. 35.0.0 makes the setting mandatory; on older releases, set a strong secret explicitly.

Upstream record: NVD · CVE.org

Is your Apache Druid deployment affected?

If you're running Apache Druid through 34.0.0, with the Kerberos authenticator, you need this patch. Book a discovery call to get covered.