CVE-2025-59390

CriticalHigh RiskPatched

Apache Druid Kerberos Auth Bypass

CVSS Score

9.8

Severity

Critical

Available Package Updates

Mavenorg.apache.druid:druidv35.0.0View on Maven

Fixed in: org.apache.druid:druid (Maven): 35.0.0

Exploit Intelligence

Weaponized

Yes

Detectable

Yes

CISA KEV

Not Listed

Risk Level

High Risk

Detection Sources

osv

Exploit Sources

github_poc

Get the Full Explanation

Sign in to get the plain English explanation including what systems are affected, how to fix it, and vendor advisory links.

Published: 11/26/2025