📦 Druid

by Apache

🔍 What is Druid?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2026-23906

CRITICAL CVSS 9.8 Feb 10, 2026

This authentication bypass vulnerability in Apache Druid allows attackers to gain unauthorized access by exploiting LDAP anonymous bind configurations. Organizations using Druid with basic security ex...

CVE-2025-59390

CRITICAL CVSS 9.8 Nov 26, 2025

Apache Druid's Kerberos authenticator uses a weak random fallback secret when cookieSignatureSecret isn't explicitly configured, allowing attackers to potentially forge authentication cookies and bypa...

CVE-2024-45384

MEDIUM CVSS 5.3 Sep 17, 2024

A padding oracle vulnerability in Apache Druid's optional druid-pac4j extension could allow attackers to manipulate session cookies. This affects Druid installations using the druid-pac4j extension in...