Apache Druid includes the ability to execute user-provided JavaScript code embedded in various types of requests. This functionality is intended for use in high-trust environments, and is disabled by default. However, in Druid 0.20.0 and earlier, it is possible for an authenticated user to send a specially-crafted request that forces Druid to run user-provided JavaScript code for that request, regardless of server configuration. This can be leveraged to execute code on the target machine with the privileges of the Druid server process.
CVE-2021-25646
Score elevated to 9.0 because EPSS predicts 99% probability of exploitation within the next 30 days (top 0.1% of all CVEs). NVD baseline CVSS 8.8 retained for reference. Confidence: see factors.
- High exploitation likelihood — EPSS 99%
No vendor fix yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for a patch.
- CVSS v3
- 8.8
- EG Score
- 9.0(high)
- EG Risk
- 85(Track)EG Risk 85/100SSVC: Track
EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).
How it’s computedSeverity90% × 45%Exploitation99% × 40%Automatability30% × 15%Action: Routine — remediate on your standard cadence. - EPSS
- 99.9%
- KEV
- Not listed
Published
January 29, 2021
Last Modified
November 21, 2024
References (32)
- security@apachehttp://packetstormsecurity.com/files/162345/Apache-Druid-0.20.0-Remote-Command-Execution.html
- security@apachehttp://www.openwall.com/lists/oss-security/2021/01/29/6
- security@apachehttps://lists.apache.org/thread.html/r04fa1ba93599487c95a8497044d37f8c02a439bfcf92b4567bfb7c8f%40%3Ccommits.druid.apache.org%3E
- security@apachehttps://lists.apache.org/thread.html/r121abe8014d381943b63c60615149d40bde9dc1c868bcee90d0d0848%40%3Ccommits.druid.apache.org%3E
- security@apachehttps://lists.apache.org/thread.html/r20e0c3b10ae2c05a3aad40f1476713c45bdefc32c920b9986b941d8f%40%3Cannounce.apache.org%3E
- security@apachehttps://lists.apache.org/thread.html/r443e2916c612fbd119839c0fc0729327d6031913a75081adac5b43ad%40%3Cdev.druid.apache.org%3E
- security@apachehttps://lists.apache.org/thread.html/r4f84b542417ea46202867c0a8b3eaf3b4cfed30e09174a52122ba210%40%3Ccommits.druid.apache.org%3E
- security@apachehttps://lists.apache.org/thread.html/r5ef625076982aee7d23c23f07717e626b73f421fba5154d1e4de15e1%40%3Ccommits.druid.apache.org%3E
- security@apachehttps://lists.apache.org/thread.html/r64431c2b97209f566b5dff92415e7afba0ed3bfab4695ebaa8a62e5d%40%3Cdev.druid.apache.org%3E
- security@apachehttps://lists.apache.org/thread.html/r7dff4790e7a5c697fc0360adf11f5aeb31cd6ad80644fffee690673c%40%3Ccommits.druid.apache.org%3E
- security@apachehttps://lists.apache.org/thread.html/r87aa94e28dd21ee2252d30c63f01ab9cb5474ee5bdd98dd8d7d734aa%40%3Ccommits.druid.apache.org%3E
- security@apachehttps://lists.apache.org/thread.html/ra4225912f501016bc5e0ac44e14b8d6779173a3a1dc7baacaabcc9ba%40%3Ccommits.druid.apache.org%3E
- security@apachehttps://lists.apache.org/thread.html/rc167d5e57f3120578718a7a458ce3e73b3830ac4efbb1b085bd06b92%40%3Cdev.druid.apache.org%3E
- security@apachehttps://lists.apache.org/thread.html/rea9436a4063927a567d698431ddae55e760c3f876c22ac5b9813685f%40%3Ccommits.druid.apache.org%3E
- security@apachehttps://lists.apache.org/thread.html/rfda8a3aa6ac06a80c5cbfdeae0fc85f88a5984e32ea05e6dda46f866%40%3Cdev.druid.apache.org%3E
Affected Packages
(1 across 1 ecosystem)
Maven(1)
| Package | Vulnerable range | Fixed in | Dependents |
|---|---|---|---|
| org.apache.druid:druid | 0.13.0-incubating ... 0.20.0 (14 versions) | 0.20.1 | — |
Data Freshness Timeline
(refreshed 5× in last 7d / 9× in last 30d)
Each row is a source pipeline that fetched or updated this CVE on that date, with what changed. For example, "NVD update" means NVD published or revised its analysis for this CVE; "MITRE cvelistV5" means we ingested or refreshed it from the CNA feed. Most recent first.
- 2026-07-23 01:58 UTCEG score recompute
- 2026-07-22 22:45 UTCEG score recompute
- 2026-07-21 15:22 UTCEPSS rescore
- 2026-07-21 15:22 UTCEPSS rescore
- 2026-07-19 02:52 UTCOSV refresh
- 2026-07-09 19:07 UTCEPSS rescore
- 2026-07-06 02:21 UTCEPSS rescore
- 2026-07-06 02:21 UTCEPSS rescore
- 2026-07-01 09:48 UTCOSV refresh
- 2026-06-17 17:51 UTCEPSS rescore
- 2026-06-15 17:46 UTCEPSS rescore
- 2026-06-13 15:13 UTCOSV refresh
- 2026-06-12 23:10 UTCEPSS rescore
- 2026-06-11 13:58 UTCEPSS rescore
- 2026-06-08 14:15 UTCEPSS rescore
- 2026-06-06 13:46 UTCEPSS rescore
- 2026-06-06 13:46 UTCEPSS rescore
- 2026-06-06 13:46 UTCEPSS rescore
- 2026-06-05 22:45 UTCEPSS rescore
- 2026-06-05 22:45 UTCEPSS rescore
- 2026-06-01 13:50 UTCEPSS rescore
- 2026-06-01 13:50 UTCEPSS rescore
- 2026-05-28 13:43 UTCEPSS rescore
- 2026-05-28 13:43 UTCEPSS rescore
- 2026-05-26 21:29 UTCEG score recompute
Publicly available exploits
(9 references)Working exploit code is in the public domain (1 Metasploit module) (7 GitHub PoCs). Defenders should treat patch urgency accordingly — public PoCs typically lead to mass-exploitation within 24-72 hours.
- GitHub PoCk7pro/CVE-2021-25646-expFirst seen Oct 4, 2024
CVE-2021-25646 Apache Druid 远程代码执行 漏洞检测和利用工具
Open source ↗ - GitHub PoCj2ekim/CVE-2021-25646First seen Dec 12, 2021
Apache Druid remote code execution vulnerability - Apache Druid 远程代码执行漏洞利用 CVE-2021-25646
Open source ↗ - GitHub PoCgivemefivw/CVE-2021-25646First seen Apr 14, 2021
CVE-2021-25646 Apache Druid 远程代码执行漏洞 Wker脚本
Open source ↗ - GitHub PoC1n7erface/PocListFirst seen Mar 11, 2021
Alibaba-Nacos-Unauthorized/ApacheDruid-RCE_CVE-2021-25646/MS-Exchange-SSRF-CVE-2021-26885/Oracle-WebLogic-CVE-2021-2109_RCE/RG-CNVD-2021-14536/RJ-SSL-VPN-UltraVires/Redis-Unauthorized-RCE/TDOA-V11.7-GetOnlineCookie/VMware-vCenter-GetAnyFile/yongyou-GRP-U8-XXE/Oracle-WebLogic-CVE-2020-14883/Oracle-WebLogic-CVE-2020-14882/Apache-Solr-GetAnyFile/F5-BIG-IP-CVE-2021-22986/Sonicwall-SSL-VPN-RCE/GitLab-Graphql-CNVD-2021-14193/D-Link-DCS-CVE-2020-25078/WLAN-AP-WEA453e-RCE/360TianQing-Unauthorized/360TianQing-SQLinjection/FanWeiOA-V8-SQLinjection/QiZhiBaoLeiJi-AnyUserLogin/QiAnXin-WangKangFirewall-RCE/金山-V8-终端安全系统/NCCloud-SQLinjection/ShowDoc-RCE
Open source ↗ - Open source ↗GitHub PoCVulnmachines/Apache-Druid-CVE-2021-25646First seen Feb 13, 2021
- Open source ↗GitHub PoClp008/CVE-2021-25646First seen Feb 3, 2021
- GitHub PoCyaunsky/cve-2021-25646First seen Feb 3, 2021
Apache Druid 远程代码执行;检测脚本
Open source ↗ - Metasploitexploit/linux/http/apache_druid_js_rce✓ verifiedFirst seen Jan 21, 2021
Apache Druid 0.20.0 Remote Command Execution
Open source ↗ - Nucleihttp/cves/2021/CVE-2021-25646.yamlFirst seen Jan 1, 2021
Apache Druid - Remote Code Execution
Open source ↗
Frequently asked(5)
What is CVE-2021-25646?
When was CVE-2021-25646 disclosed?
Is CVE-2021-25646 actively exploited?
What is the CVSS score of CVE-2021-25646?
How do I remediate CVE-2021-25646?
Dependency Blast Radius
See which npm, PyPI, Go, and Maven packages are affected by CVE-2021-25646
Is Your Infrastructure Affected by CVE-2021-25646?
EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.