CVE-2025-59390
Apache Druid: Kerberos authenticator falls back to a weak cookie signing secret
Technology
Apache Druid
CVSS Score
9.8 / 10.0
Affected Versions
Apache Druid through 34.0.0, with the Kerberos authenticator
Upstream Fix
35.0.0
Published
November 26, 2025
OSSeva Coverage
Fixed upstream
Description
If druid.auth.authenticator.kerberos.cookieSignatureSecret is not set, the Kerberos authenticator generates a signing secret with ThreadLocalRandom, which is not cryptographically secure, so an attacker may predict or brute force it and forge authentication cookies. 35.0.0 makes the setting mandatory; on older releases, set a strong secret explicitly.
Is your Apache Druid deployment affected?
If you're running Apache Druid through 34.0.0, with the Kerberos authenticator, you need this patch. Book a discovery call to get covered.