{"api_version":"v1","generated_at":"2026-10-06T22:50:00+00:00","product":{"cve_count":11,"evidence_gap_note":"This identity is present in BlackTree CVE records, but no product-specific publisher support or retirement history is currently registered in Lifecycle.","id":"security:cve-apache-software-foundation-apache-druid-08bff36181fe","lifecycle_state":"evidence_gap","linked_lifecycle_url":null,"name":"Apache Druid","next_cursor":null,"observations":[{"affected":"0.17.0 < 36.0.0","affected_versions_present":true,"cve_id":"CVE-2026-23906","cve_url":"https://cve.blacktree.nl/cve/CVE-2026-23906","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2026-02-12T04:45:28.979Z","patch_url":"","primary_source":"","published":"2026-02-10T09:28:09.007Z"},{"affected":"\u2264 34.0.0","affected_versions_present":true,"cve_id":"CVE-2025-59390","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-59390","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-12-11T14:24:14.505Z","patch_url":"","primary_source":"","published":"2025-11-26T08:50:07.322Z"},{"affected":"< 31.0.2; 32.0.0","affected_versions_present":true,"cve_id":"CVE-2025-27888","cve_url":"https://cve.blacktree.nl/cve/CVE-2025-27888","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-03-25T15:18:04.929Z","patch_url":"","primary_source":"","published":"2025-03-20T11:29:00.730Z"},{"affected":"\u2264 30.0.0","affected_versions_present":true,"cve_id":"CVE-2024-45537","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-45537","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-03-14T15:09:00.250Z","patch_url":"","primary_source":"","published":"2024-09-17T18:37:49.823Z"},{"affected":"0.18.0 \u2264 30.0.0","affected_versions_present":true,"cve_id":"CVE-2024-45384","cve_url":"https://cve.blacktree.nl/cve/CVE-2024-45384","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-03-14T19:45:27.172Z","patch_url":"","primary_source":"","published":"2024-09-17T18:36:00.411Z"},{"affected":"unspecified \u2264 0.22.1","affected_versions_present":true,"cve_id":"CVE-2022-28889","cve_url":"https://cve.blacktree.nl/cve/CVE-2022-28889","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-03T06:10:56.784Z","patch_url":"","primary_source":"","published":"2022-07-07T18:35:22.000Z"},{"affected":"Apache Druid \u2264 0.22.1","affected_versions_present":true,"cve_id":"CVE-2021-44791","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-44791","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-04T04:32:13.108Z","patch_url":"","primary_source":"","published":"2022-07-07T18:35:16.000Z"},{"affected":"0.21.1 and earlier \u2264 0.21.1","affected_versions_present":true,"cve_id":"CVE-2021-36749","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-36749","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-04T01:01:59.216Z","patch_url":"","primary_source":"","published":"2021-09-24T09:30:11.000Z"},{"affected":"Apache Druid \u2264 0.20.2","affected_versions_present":true,"cve_id":"CVE-2021-26920","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-26920","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2024-08-03T20:33:41.311Z","patch_url":"","primary_source":"","published":"2021-07-02T07:20:13.000Z"},{"affected":"Apache Druid \u2264 0.20.1","affected_versions_present":true,"cve_id":"CVE-2021-26919","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-26919","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-02-13T16:27:55.797Z","patch_url":"","primary_source":"","published":"2021-03-30T07:50:10.000Z"},{"affected":"0.20.0 and earlier \u2264 0.20.0","affected_versions_present":true,"cve_id":"CVE-2021-25646","cve_url":"https://cve.blacktree.nl/cve/CVE-2021-25646","fixed":"No fixed version is explicitly recorded in the structured CVE data.","last_modified":"2025-02-13T16:27:49.264Z","patch_url":"","primary_source":"","published":"2021-01-29T19:15:12.000Z"}],"source_generated_at":"2026-10-06T06:22:27.870Z","vendor":"Apache Software Foundation"}}
