This is an automated email from the ASF dual-hosted git repository.

kfaraz pushed a commit to branch 38.0.0-fix-cves
in repository https://gitbox.apache.org/repos/asf/druid.git

commit bf5de82fbaad08749e6472c2c696b7eb95801766
Author: Kashif Faraz <[email protected]>
AuthorDate: Mon Sep 14 15:06:49 2026 +0530

    Suppress CVEs that are not applicable to Druid
---
 owasp-dependency-check-suppressions.xml | 171 ++++++++++++++++++++++++++++++++
 1 file changed, 171 insertions(+)

diff --git a/owasp-dependency-check-suppressions.xml 
b/owasp-dependency-check-suppressions.xml
index 0be1d8f33d4..5c91911e338 100644
--- a/owasp-dependency-check-suppressions.xml
+++ b/owasp-dependency-check-suppressions.xml
@@ -19,6 +19,20 @@
   -->
 <suppressions 
xmlns="https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd";>
   <!-- False positives -->
+  <suppress>
+    <!-- False positive: the scanner matches the Java client version "1.2.0" 
against
+         cpe:2.3:a:memcached:memcached:1.2.0 (the C memcached server daemon).
+         elasticache-java-cluster-client is a Java Memcached CLIENT library; 
Druid uses it
+         solely to send cache get/set/delete commands to a remote Memcached 
server.
+         Druid does not run or embed a Memcached server process, so all CVEs 
mapped to
+         the memcached:memcached CPE are false positives for this artifact. -->
+    <notes><![CDATA[
+      file name: elasticache-java-cluster-client-1.2.0.jar
+    ]]></notes>
+    <packageUrl 
regex="true">^pkg:maven/com\.amazonaws/elasticache-java-cluster-client@.*$</packageUrl>
+    <cpe>cpe:/a:memcached:memcached</cpe>
+  </suppress>
+
   <suppress>
     <notes><![CDATA[
      file name: json-path-2.9.0.jar jackson-core-2.12.7.jar
@@ -403,6 +417,18 @@
      <cve>CVE-2022-3171</cve>
    </suppress>
 
+  <suppress>
+    <!-- CVE-2022-3171: False positive. This CVE affects Google's 
protobuf-java (com.google.protobuf),
+         but the scanner matches it against dev.cel:protobuf via the broad 
protobuf CPE.
+         dev.cel:protobuf is part of the Common Expression Language library 
and is unrelated
+         to Google's protobuf-java parsing code that contains the 
vulnerability. -->
+    <notes><![CDATA[
+      file name: protobuf-0.13.0.jar
+    ]]></notes>
+    <packageUrl regex="true">^pkg:maven/dev\.cel/protobuf@.*$</packageUrl>
+    <cve>CVE-2022-3171</cve>
+  </suppress>
+
    <suppress>
      <notes><![CDATA[
      file name: ansi-regex:5.0.0
@@ -768,4 +794,149 @@
     <packageUrl regex="true">^pkg:maven/io\.grpc/grpc-.*@.*$</packageUrl>
     <cve>CVE-2026-33186</cve> <!-- Only applicable to gRPC Go 
(google.golang.org/grpc < 1.79.3), not gRPC Java - 
https://nvd.nist.gov/vuln/detail/CVE-2026-33186 -->
   </suppress>
+
+  <suppress>
+    <!-- GHSA-w5hq-g745-h8pq: Missing bounds check in uuid v3/v5/v6 when the 
optional buf
+         argument is provided. Druid's web console uses only uuidv4() with no 
buf argument
+         (web-console/src/druid-models/workbench-query/workbench-query.ts), so 
the
+         vulnerable code path is never exercised.
+         Update to version 11.1.1 or 12.0.1 to remove this suppression
+          -->
+    <notes><![CDATA[
+      file name: package-lock.json (pkg:npm/[email protected])
+    ]]></notes>
+    <packageUrl regex="true">^pkg:npm/uuid@.*$</packageUrl>
+    <vulnerabilityName>GHSA-w5hq-g745-h8pq</vulnerabilityName>
+  </suppress>
+
+  <suppress>
+    <!-- CVE-2026-53914: Unsafe deserialization in Kotlin's build cache 
metadata (Kotlin compiler/Gradle plugin).
+         This is a build-toolchain vulnerability, not a runtime stdlib issue. 
Druid has no Kotlin source files;
+         kotlin-stdlib is a transitive runtime dependency (via Iceberg) and 
Druid never invokes Kotlin's build cache. -->
+    <notes><![CDATA[
+      file name: kotlin-stdlib-2.4.10.jar
+    ]]></notes>
+    <packageUrl 
regex="true">^pkg:maven/org\.jetbrains\.kotlin/kotlin-stdlib@.*$</packageUrl>
+    <cve>CVE-2026-53914</cve>
+  </suppress>
+
+  <suppress>
+    <!-- CVE-2026-33117: Vulnerability in Azure SDK for Java's Key Vault Keys 
local cryptographic verification path.
+         The CVE fires against azure-core, azure-core-http-netty, 
azure-identity, and azure-json due to broad CPE
+         matching, but none of these jars contain the vulnerable Key Vault 
code path. Druid uses these artifacts
+         for blob storage auth only and does not use the Key Vault 
cryptography client. -->
+    <notes><![CDATA[
+      file name: azure-core-1.58.1.jar azure-core-http-netty-1.16.5.jar 
azure-identity-1.18.4.jar azure-json-1.5.1.jar
+    ]]></notes>
+    <packageUrl regex="true">^pkg:maven/com\.azure/azure-.*@.*$</packageUrl>
+    <cve>CVE-2026-33117</cve>
+  </suppress>
+
+  <suppress>
+    <!-- CVE-2026-49845: SQL injection in Hive Metastore partition-name 
resolution.
+         CVE-2026-53561: SAML bearer-token authentication bypass in 
HiveServer2.
+         CVE-2026-55976: SSRF via avro.schema.url in Avro SerDe schema 
resolution.
+         All three affect Apache Hive server components (Metastore, 
HiveServer2).
+         Druid uses hive-storage-api only for the Murmur3 hash utility
+         (BloomKFilter.java) and ORC/Parquet column type definitions — it does 
not
+         run or connect to a Hive Metastore or HiveServer2. -->
+    <notes><![CDATA[
+      file name: hive-storage-api-4.2.0.jar
+    ]]></notes>
+    <packageUrl 
regex="true">^pkg:maven/org\.apache\.hive/hive-storage-api@.*$</packageUrl>
+    <cve>CVE-2026-49845</cve>
+    <cve>CVE-2026-53561</cve>
+    <cve>CVE-2026-55976</cve>
+  </suppress>
+
+  <suppress>
+    <!-- CVE-2026-54512, CVE-2026-54513: PolymorphicTypeValidator bypass in 
jackson-databind when
+         polymorphic typing is enabled with generic type parameters or array 
subtypes.
+         These CVEs affect jackson-databind shaded inside hadoop/parquet jars,
+         not Druid's own jackson-databind (2.22.x).
+         CVE-2026-68497: Not yet published in NVD, suppressed as appearing 
only inside shaded jars -->
+    <notes><![CDATA[
+      file name: hadoop-client-runtime-3.5.0.jar (shaded jackson-databind 
2.18.6)
+                 parquet-jackson-1.18.0.jar (shaded jackson-databind 2.22.1)
+    ]]></notes>
+    <filePath 
regex="true">.*/(hadoop-client-runtime|parquet-jackson)-[0-9][^/]*\.jar/META-INF/maven/com\.fasterxml\.jackson\.core/jackson-databind/pom\.xml$</filePath>
+    <cve>CVE-2026-54512</cve>
+    <cve>CVE-2026-54513</cve>
+    <cve>CVE-2026-68497</cve>
+  </suppress>
+
+  <suppress>
+    <!-- CVE-2026-2332: Jetty HTTP/1.1 request smuggling via chunk extension 
quoted strings.
+         CVE-2026-10050: Jetty Digest auth password encoding using ISO-8859-1.
+         Both affect Jetty shaded inside hadoop-client-runtime-3.5.0.jar. 
Druid cannot upgrade
+         the Jetty version inside this shaded jar. The shaded Jetty is used 
only for Hadoop's
+         internal HTTP server (WebHDFS, etc.), not for Druid's own HTTP server 
(Jetty 12.x).
+         Druid does not use Hadoop's embedded Jetty server or Digest auth. -->
+    <notes><![CDATA[
+      file name: hadoop-client-runtime-3.5.0.jar (shaded org.eclipse.jetty* 
9.4.58.v20250814)
+    ]]></notes>
+    <filePath 
regex="true">.*/(hadoop-client-runtime)-[0-9][^/]*\.jar/META-INF/maven/org\.eclipse\.jetty[^/]*/[^/]*/pom\.xml$</filePath>
+    <cve>CVE-2026-2332</cve>
+    <cve>CVE-2026-10050</cve>
+  </suppress>
+
+  <suppress>
+    <!-- CVE-2026-56741, CVE-2026-56740: DoS via JLine Telnet server (NAWS 
terminal dimensions and
+         NEW-ENVIRON flooding). JLine is shaded inside 
hadoop-client-runtime-3.5.0.jar and is used
+         only for Hadoop's interactive CLI shell. Druid does not expose a 
JLine Telnet server endpoint. -->
+    <notes><![CDATA[
+      file name: hadoop-client-runtime-3.5.0.jar (shaded jline 3.9.0)
+    ]]></notes>
+    <filePath 
regex="true">.*/(hadoop-client-runtime)-[0-9][^/]*\.jar/META-INF/maven/org\.jline/jline[^/]*/pom\.xml$</filePath>
+    <cve>CVE-2026-56741</cve>
+    <cve>CVE-2026-56740</cve>
+  </suppress>
+
+  <suppress>
+    <!-- CVE-2026-24051, CVE-2026-39883, CVE-2026-29181: All three affect the 
OpenTelemetry Go SDK
+         (opentelemetry-go), not any Java library. The scanner matches 
opentelemetry-gcp-resources
+         (a Java artifact) against the Go SDK CPE due to the shared 
"opentelemetry" product name.
+         Druid's google-extensions use the Java opentelemetry-gcp-resources 
for GCP resource
+         detection; the vulnerable PATH hijacking and baggage-header 
amplification code exists
+         only in the Go implementation. -->
+    <notes><![CDATA[
+      file name: opentelemetry-gcp-resources-1.37.0-alpha.jar
+    ]]></notes>
+    <packageUrl 
regex="true">^pkg:maven/io\.opentelemetry\.contrib/opentelemetry-gcp-resources@.*$</packageUrl>
+    <cve>CVE-2026-24051</cve>
+    <cve>CVE-2026-39883</cve>
+    <cve>CVE-2026-29181</cve>
+  </suppress>
+
+  <suppress>
+    <!-- CVE-2026-40542, CVE-2026-71290: Vulnerabilities in Apache HttpClient 
5 (SCRAM mutual auth
+         and async hostname verification). CVE-2026-54399, CVE-2026-54428: DoS 
in Apache HttpComponents
+         Core 5 (excessive headers and HTTP/2 HPACK). All four affect 
httpclient5/httpcore5 shaded
+         inside docker-java-transport-zerodep-3.7.1.jar (a test-scoped 
dependency used only by
+         druid-testcontainers for Docker container management in tests). These 
are not present in
+         Druid's production runtime classpath. -->
+    <notes><![CDATA[
+      file name: docker-java-transport-zerodep-3.7.1.jar (shaded httpclient5 
5.5.1 and httpcore5 5.3.6)
+    ]]></notes>
+    <packageUrl 
regex="true">^pkg:maven/org\.apache\.httpcomponents\.(client5/httpclient5|core5/httpcore5)@.*$</packageUrl>
+    <cve>CVE-2026-40542</cve>
+    <cve>CVE-2026-71290</cve>
+    <cve>CVE-2026-54399</cve>
+    <cve>CVE-2026-54428</cve>
+  </suppress>
+
+  <suppress>
+    <!-- CVE-2026-87823: Out-of-bounds memory read in ByteBuffer frame-size 
methods via negative offset values.
+         CVE-2026-87795: Out-of-bounds memory read in ZstdDictCompress 
constructor via unvalidated offset/length.
+         Both are fixed in zstd-jni 1.5.7-14. Suppressed until zstd-jni is 
upgraded.
+         Based on the analysis in 
https://github.com/apache/druid/pull/20236#issuecomment-5646494509,
+         this vulnerability should not affect Druid since the relevant code 
paths do not get activated
+          -->
+    <notes><![CDATA[
+      file name: zstd-jni-1.5.7-11.jar
+    ]]></notes>
+    <packageUrl 
regex="true">^pkg:maven/com\.github\.luben/zstd-jni@.*$</packageUrl>
+    <cve>CVE-2026-87823</cve>
+    <cve>CVE-2026-87795</cve>
+  </suppress>
 </suppressions>


---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]

Reply via email to