This is an automated email from the ASF dual-hosted git repository.
kfaraz pushed a commit to branch 38.0.0
in repository https://gitbox.apache.org/repos/asf/druid.git
The following commit(s) were added to refs/heads/38.0.0 by this push:
new 5f2587d999f release: Suppress CVEs that are not applicable to Druid 38
(#20335)
5f2587d999f is described below
commit 5f2587d999f557f82cf8965e0cf457a7a7adfbeb
Author: Kashif Faraz <[email protected]>
AuthorDate: Tue Sep 22 00:01:28 2026 +0530
release: Suppress CVEs that are not applicable to Druid 38 (#20335)
Relevant packages:
- Netty codec/server vulnerabilities in Netty 3.x
- Memcached client false positives
- shaded Hadoop/Parquet issues
---
owasp-dependency-check-suppressions.xml | 258 ++++++++++++++++++++++++++++++++
1 file changed, 258 insertions(+)
diff --git a/owasp-dependency-check-suppressions.xml
b/owasp-dependency-check-suppressions.xml
index 0be1d8f33d4..125c9b6c793 100644
--- a/owasp-dependency-check-suppressions.xml
+++ b/owasp-dependency-check-suppressions.xml
@@ -19,6 +19,20 @@
-->
<suppressions
xmlns="https://jeremylong.github.io/DependencyCheck/dependency-suppression.1.3.xsd">
<!-- False positives -->
+ <suppress>
+ <!-- False positive: the scanner matches the Java client version "1.2.0"
against
+ cpe:2.3:a:memcached:memcached:1.2.0 (the C memcached server daemon).
+ elasticache-java-cluster-client is a Java Memcached CLIENT library;
Druid uses it
+ solely to send cache get/set/delete commands to a remote Memcached
server.
+ Druid does not run or embed a Memcached server process, so all CVEs
mapped to
+ the memcached:memcached CPE are false positives for this artifact. -->
+ <notes><![CDATA[
+ file name: elasticache-java-cluster-client-1.2.0.jar
+ ]]></notes>
+ <packageUrl
regex="true">^pkg:maven/com\.amazonaws/elasticache-java-cluster-client@.*$</packageUrl>
+ <cpe>cpe:/a:memcached:memcached</cpe>
+ </suppress>
+
<suppress>
<notes><![CDATA[
file name: json-path-2.9.0.jar jackson-core-2.12.7.jar
@@ -274,8 +288,39 @@
<cve>CVE-2025-58057</cve> <!-- Netty 3.x not affected; compression issue
only in 4.x -->
<cve>CVE-2026-33870</cve> <!-- We don't use HttpPostRequestDecoder -->
<cve>CVE-2026-33871</cve> <!-- Netty 3.x not affected; HTTP/2 issues only
in 4.x -->
+ <cve>CVE-2026-44893</cve> <!-- We don't use the HAProxy codec -->
+ <cve>CVE-2026-44250</cve> <!-- We don't use the Redis codec -->
+ <cve>CVE-2026-48059</cve> <!-- We don't use the HAProxy codec -->
+ <cve>CVE-2026-44890</cve> <!-- We don't use the Redis codec -->
+ <cve>CVE-2026-44891</cve> <!-- We don't use the STOMP codec -->
+ <cve>CVE-2026-50011</cve> <!-- We don't use the Redis codec -->
+ <cve>CVE-2026-59901</cve> <!-- We don't use Netty's Bzip2Decoder; Druid
uses Apache Commons Compress for bzip2 -->
+ <cve>CVE-2026-62380</cve> <!-- We don't use the SOCKS codec; Druid uses
HTTP CONNECT proxy tunneling -->
+ <cve>CVE-2026-59898</cve> <!-- Server-side WebSocket vulnerability;
Druid's HTTP server is Jetty, not Netty -->
+ <cve>CVE-2026-59899</cve> <!-- Server-side HttpContentEncoder
vulnerability; Druid uses Netty 3.x as HTTP client only -->
+ <cve>CVE-2026-42587</cve> <!-- Affects brotli/zstd/snappy decompression
added in Netty 4.x; Netty 3.x only supports gzip/deflate -->
+ <cve>CVE-2026-42586</cve> <!-- We don't use the Redis codec -->
+ <cve>CVE-2026-44248</cve> <!-- We don't use the MQTT codec -->
+ <cve>CVE-2026-44249</cve> <!-- We don't use Netty's IpSubnetFilterRule;
Druid uses Jetty for HTTP access control -->
+ <cve>CVE-2026-45416</cve> <!-- Server-side TLS SNI vulnerability; Druid
uses Netty 3.x as TLS client only, never as a server -->
+ <cve>CVE-2026-42581</cve> <!-- Server-side HTTP request smuggling; Druid's
HTTP server is Jetty, not Netty -->
+ <cve>CVE-2026-45674</cve> <!-- Affects netty-resolver-dns which Druid
doesn't use; Druid uses JDK DNS resolution -->
+ <cve>CVE-2026-48006</cve> <!-- We don't use the Redis codec -->
+ <cve>CVE-2026-42585</cve> <!-- Server-side HTTP request smuggling; Druid's
HTTP server is Jetty, not Netty -->
+ <cve>CVE-2026-42584</cve> <!-- Druid uses Netty3 for internal
communication only, which does not satisfy any of the prerequisites of this
vulnerability (pipeline requests, send HEAD, use 1xx responses) -->
+ <cve>CVE-2026-46340</cve> <!-- We don't use SCTP transport; Druid uses
TCP/NIO -->
+ <cve>CVE-2026-42583</cve> <!-- We don't use Netty's Lz4FrameDecoder; Druid
uses lz4-java directly -->
+ <cve>CVE-2026-48043</cve> <!-- We don't use netty-codec-http2 directly;
Druid's HTTP/2 is served by Jetty -->
+ <cve>CVE-2026-56822</cve> <!-- We don't use netty-handler-ssl-ocsp -->
+ <cve>CVE-2026-56821</cve> <!-- We don't use netty-handler-ssl-ocsp -->
+ <cve>CVE-2026-47691</cve> <!-- Affects netty-resolver-dns which Druid
doesn't use; Druid uses JDK DNS resolution -->
+ <cve>CVE-2026-56820</cve> <!-- We don't use netty-handler-ssl-ocsp -->
+ <cve>CVE-2026-50010</cve> <!-- Druid's Netty 3.x HTTP client does not use
SslContextBuilder; gRPC/AWS SDK paths use managed SSL contexts -->
+ <cve>CVE-2026-42578</cve> <!-- We don't use HttpProxyHandler; Druid uses a
custom HTTP CONNECT tunnel via HttpClientCodec -->
+ <cve>CVE-2026-42579</cve> <!-- We don't use netty-codec-dns; Druid uses
JDK DNS resolution -->
</suppress>
+
<suppress>
<notes><![CDATA[
file name: icu4j-77.1.jar
@@ -403,6 +448,18 @@
<cve>CVE-2022-3171</cve>
</suppress>
+ <suppress>
+ <!-- CVE-2022-3171: False positive. This CVE affects Google's
protobuf-java (com.google.protobuf),
+ but the scanner matches it against dev.cel:protobuf via the broad
protobuf CPE.
+ dev.cel:protobuf is part of the Common Expression Language library
and is unrelated
+ to Google's protobuf-java parsing code that contains the
vulnerability. -->
+ <notes><![CDATA[
+ file name: protobuf-0.13.0.jar
+ ]]></notes>
+ <packageUrl regex="true">^pkg:maven/dev\.cel/protobuf@.*$</packageUrl>
+ <cve>CVE-2022-3171</cve>
+ </suppress>
+
<suppress>
<notes><![CDATA[
file name: ansi-regex:5.0.0
@@ -471,6 +528,14 @@
<cve>CVE-2021-4277</cve>
</suppress>
+ <suppress>
+ <notes><![CDATA[
+ file name: async-http-client-3.0.2.jar
+ ]]></notes>
+ <packageUrl
regex="true">^pkg:maven/org\.asynchttpclient/[email protected]$</packageUrl>
+ <cve>CVE-2026-45300</cve> <!-- Cookie leak on cross-origin redirect: Druid
does not configure automatic redirect following or a cookie store in AHC;
redirects are handled manually at application level in ServiceClientImpl
without forwarding cookies -->
+ </suppress>
+
<!-- the remaining uses of vulnerable okio are in contrib-extensions -->
<suppress>
<notes><![CDATA[
@@ -768,4 +833,197 @@
<packageUrl regex="true">^pkg:maven/io\.grpc/grpc-.*@.*$</packageUrl>
<cve>CVE-2026-33186</cve> <!-- Only applicable to gRPC Go
(google.golang.org/grpc < 1.79.3), not gRPC Java -
https://nvd.nist.gov/vuln/detail/CVE-2026-33186 -->
</suppress>
+
+ <suppress>
+ <!-- GHSA-w5hq-g745-h8pq: Missing bounds check in uuid v3/v5/v6 when the
optional buf
+ argument is provided. Druid's web console uses only uuidv4() with no
buf argument
+ (web-console/src/druid-models/workbench-query/workbench-query.ts), so
the
+ vulnerable code path is never exercised.
+ Update to version 11.1.1 or 12.0.1 to remove this suppression
+ -->
+ <notes><![CDATA[
+ file name: package-lock.json (pkg:npm/[email protected])
+ ]]></notes>
+ <packageUrl regex="true">^pkg:npm/uuid@.*$</packageUrl>
+ <vulnerabilityName>GHSA-w5hq-g745-h8pq</vulnerabilityName>
+ </suppress>
+
+ <suppress>
+ <!-- CVE-2026-53914: Unsafe deserialization in Kotlin's build cache
metadata (Kotlin compiler/Gradle plugin).
+ This is a build-toolchain vulnerability, not a runtime stdlib issue.
Druid has no Kotlin source files;
+ kotlin-stdlib is a transitive runtime dependency (via Iceberg) and
Druid never invokes Kotlin's build cache. -->
+ <notes><![CDATA[
+ file name: kotlin-stdlib-2.4.10.jar
+ ]]></notes>
+ <packageUrl
regex="true">^pkg:maven/org\.jetbrains\.kotlin/kotlin-stdlib@.*$</packageUrl>
+ <cve>CVE-2026-53914</cve>
+ </suppress>
+
+ <suppress>
+ <!-- CVE-2026-33117: Vulnerability in Azure SDK for Java's Key Vault Keys
local cryptographic verification path.
+ The CVE fires against azure-core, azure-core-http-netty,
azure-identity, and azure-json due to broad CPE
+ matching, but none of these jars contain the vulnerable Key Vault
code path. Druid uses these artifacts
+ for blob storage auth only and does not use the Key Vault
cryptography client. -->
+ <notes><![CDATA[
+ file name: azure-core-1.58.1.jar azure-core-http-netty-1.16.5.jar
azure-identity-1.18.4.jar azure-json-1.5.1.jar
+ ]]></notes>
+ <packageUrl
regex="true">^pkg:maven/com\.azure/(azure-core|azure-core-http-netty|azure-identity|azure-json)@.*$</packageUrl>
+ <cve>CVE-2026-33117</cve>
+ </suppress>
+
+ <suppress>
+ <!-- CVE-2026-49845: SQL injection in Hive Metastore partition-name
resolution.
+ CVE-2026-53561: SAML bearer-token authentication bypass in
HiveServer2.
+ CVE-2026-55976: SSRF via avro.schema.url in Avro SerDe schema
resolution.
+ All three affect Apache Hive server components (Metastore,
HiveServer2).
+ Druid does not run Hive Metastore or HiveServer2 itself -->
+ <notes><![CDATA[
+ file name: hive-storage-api-4.2.0.jar
+ ]]></notes>
+ <packageUrl
regex="true">^pkg:maven/org\.apache\.hive/hive-storage-api@.*$</packageUrl>
+ <cve>CVE-2026-49845</cve>
+ <cve>CVE-2026-53561</cve>
+ <cve>CVE-2026-55976</cve>
+ </suppress>
+
+ <suppress>
+ <!-- CVE-2026-54512, CVE-2026-54513: PolymorphicTypeValidator bypass in
jackson-databind when
+ polymorphic typing is enabled with generic type parameters or array
subtypes.
+ These CVEs affect jackson-databind shaded inside hadoop/parquet jars,
+ not Druid's own jackson-databind (2.22.x).
+ CVE-2026-68497: Not yet published in NVD, suppressed as appearing
only inside shaded jars -->
+ <notes><![CDATA[
+ file name: hadoop-client-runtime-3.5.0.jar (shaded jackson-databind
2.18.6)
+ parquet-jackson-1.18.0.jar (shaded jackson-databind 2.22.1)
+ ]]></notes>
+ <filePath
regex="true">(?:.*/)?(hadoop-client-runtime|parquet-jackson)-[0-9][^/]*\.jar/META-INF/maven/com\.fasterxml\.jackson\.core/jackson-databind/pom\.xml$</filePath>
+ <cve>CVE-2026-54512</cve>
+ <cve>CVE-2026-54513</cve>
+ <cve>CVE-2026-68497</cve>
+ </suppress>
+
+ <suppress>
+ <!-- CVE-2026-2332: Jetty HTTP/1.1 request smuggling via chunk extension
quoted strings.
+ CVE-2026-10050: Jetty Digest auth password encoding using ISO-8859-1.
+ Both affect Jetty shaded inside hadoop-client-runtime-3.5.0.jar.
Druid cannot upgrade
+ the Jetty version inside this shaded jar. The shaded Jetty is used
only for Hadoop's
+ internal HTTP server (WebHDFS, etc.), not for Druid's own HTTP server
(Jetty 12.x).
+ Druid does not use Hadoop's embedded Jetty server or Digest auth. -->
+ <notes><![CDATA[
+ file name: hadoop-client-runtime-3.5.0.jar (shaded org.eclipse.jetty*
9.4.58.v20250814)
+ ]]></notes>
+ <filePath
regex="true">(?:.*/)?hadoop-client-runtime-[0-9][^/]*\.jar/META-INF/maven/org\.eclipse\.jetty[^/]*/[^/]*/pom\.xml$</filePath>
+ <cve>CVE-2026-2332</cve>
+ <cve>CVE-2026-10050</cve>
+ </suppress>
+
+ <suppress>
+ <!-- CVE-2026-56741, CVE-2026-56740: DoS via JLine Telnet server (NAWS
terminal dimensions and
+ NEW-ENVIRON flooding). JLine is shaded inside
hadoop-client-runtime-3.5.0.jar and is used
+ only for Hadoop's interactive CLI shell. Druid does not expose a
JLine Telnet server endpoint. -->
+ <notes><![CDATA[
+ file name: hadoop-client-runtime-3.5.0.jar (shaded jline 3.9.0)
+ ]]></notes>
+ <filePath
regex="true">.*/(hadoop-client-runtime)-[0-9][^/]*\.jar/META-INF/maven/org\.jline/jline[^/]*/pom\.xml$</filePath>
+ <cve>CVE-2026-56741</cve>
+ <cve>CVE-2026-56740</cve>
+ </suppress>
+
+ <suppress>
+ <!-- CVE-2026-24051, CVE-2026-39883, CVE-2026-29181: All three affect the
OpenTelemetry Go SDK
+ (opentelemetry-go), not any Java library. The scanner matches
opentelemetry-gcp-resources
+ (a Java artifact) against the Go SDK CPE due to the shared
"opentelemetry" product name.
+ Druid's google-extensions use the Java opentelemetry-gcp-resources
for GCP resource
+ detection; the vulnerable PATH hijacking and baggage-header
amplification code exists
+ only in the Go implementation. -->
+ <notes><![CDATA[
+ file name: opentelemetry-gcp-resources-1.37.0-alpha.jar
+ ]]></notes>
+ <packageUrl
regex="true">^pkg:maven/io\.opentelemetry\.contrib/opentelemetry-gcp-resources@.*$</packageUrl>
+ <cve>CVE-2026-24051</cve>
+ <cve>CVE-2026-39883</cve>
+ <cve>CVE-2026-29181</cve>
+ </suppress>
+
+ <suppress>
+ <!-- CVE-2026-40542, CVE-2026-71290: Vulnerabilities in Apache HttpClient
5 (SCRAM mutual auth
+ and async hostname verification). CVE-2026-54399, CVE-2026-54428: DoS
in Apache HttpComponents
+ Core 5 (excessive headers and HTTP/2 HPACK). All four affect
httpclient5/httpcore5 shaded
+ inside docker-java-transport-zerodep-3.7.1.jar (a test-scoped
dependency used only by
+ druid-testcontainers for Docker container management in tests). These
are not present in
+ Druid's production runtime classpath. -->
+ <notes><![CDATA[
+ file name: docker-java-transport-zerodep-3.7.1.jar (shaded httpclient5
5.5.1 and httpcore5 5.3.6)
+ ]]></notes>
+ <packageUrl
regex="true">^pkg:maven/org\.apache\.httpcomponents\.(client5/httpclient5|core5/(httpcore5|httpcore5-h2))@.*$</packageUrl>
+ <cve>CVE-2026-40542</cve>
+ <cve>CVE-2026-71290</cve>
+ <cve>CVE-2026-54399</cve>
+ <cve>CVE-2026-54428</cve>
+ </suppress>
+
+ <suppress>
+ <!-- CVE-2026-87823: Out-of-bounds memory read in ByteBuffer frame-size
methods via negative offset values.
+ CVE-2026-87795: Out-of-bounds memory read in ZstdDictCompress
constructor via unvalidated offset/length.
+ Both are fixed in zstd-jni 1.5.7-14. Suppressed until zstd-jni is
upgraded.
+ Based on the analysis in
https://github.com/apache/druid/pull/20236#issuecomment-5646494509,
+ this vulnerability should not affect Druid since the relevant code
paths do not get activated
+ -->
+ <notes><![CDATA[
+ file name: zstd-jni-1.5.7-7.jar
+ ]]></notes>
+ <packageUrl
regex="true">^pkg:maven/com\.github\.luben/zstd-jni@1\.5\.7-7$</packageUrl>
+ <cve>CVE-2026-87823</cve>
+ <cve>CVE-2026-87795</cve>
+ </suppress>
+
+ <suppress>
+ <!-- CVE-2026-90559: Out-of-bounds write in Snappy.uncompress(ByteBuffer,
ByteBuffer) — the
+ destination buffer capacity is never validated against the
decompressed size, allowing
+ attacker-controlled compressed input to crash the JVM. No fix is
available upstream yet
+ (xerial/snappy-java#728, opened 2026-08-14).
+ Druid does not call org.xerial.snappy directly; snappy-java is a
transitive dependency
+ (pulled in by Kafka, Parquet, etc.). Druid's own snappy decompression
uses Apache Commons
+ Compress (FramedSnappyCompressorInputStream), not the xerial
Snappy.uncompress path.
+ The vulnerable ByteBuffer overload is therefore not reachable from
Druid code. -->
+ <notes><![CDATA[
+ file name: snappy-java-1.1.10.7.jar
+ ]]></notes>
+ <packageUrl
regex="true">^pkg:maven/org\.xerial\.snappy/snappy-java@.*$</packageUrl>
+ <cve>CVE-2026-90559</cve>
+ </suppress>
+
+ <suppress>
+ <!-- CVE-2026-73334: Improper KMS URL validation in
org.apache.parquet.crypto.keytools —
+ a file-controlled KMS URL is forwarded to a pluggable KmsClient
without host validation,
+ allowing a malicious Parquet file to redirect KMS token requests to
an attacker-controlled
+ host. Affects parquet 1.12 through 1.18; fix expected in 1.19.
+ Druid does not use Parquet's envelope encryption or the
crypto.keytools package at all.
+ Druid uses Parquet only for columnar data read/write with no
KmsClient integration. -->
+ <notes><![CDATA[
+ file name: parquet-column-1.16.0.jar parquet-common-1.16.0.jar
+ ]]></notes>
+ <packageUrl
regex="true">^pkg:maven/org\.apache\.parquet/parquet-.*@.*$</packageUrl>
+ <cve>CVE-2026-73334</cve>
+ </suppress>
+
+ <suppress>
+ <!-- CVE-2026-79993: deleteContainer opcode processed without ACL
verification — unauthenticated
+ attacker with TCP access to port 2181 can delete empty persistent
znodes. Server-side only.
+ CVE-2026-59739: SetWatches reconnect replay skips ACL checks on the
server, leaking
+ restricted znode path names to watchers on reconnect. Server-side
only.
+ CVE-2026-59969: Quorum TLS hostname verification bypassed in FIPS mode
+ (requires sslQuorum=true + zookeeper.fips-mode=true). Affects
server-to-server
+ quorum communication only.
+ All three are fixed in ZooKeeper 3.8.7. Druid uses ZooKeeper as a
CLIENT only
+ (service discovery, leader election coordination) and does not run a
ZooKeeper
+ server or quorum. None of these code paths execute in the ZooKeeper
client library. -->
+ <notes><![CDATA[
+ file name: zookeeper-3.8.6.jar zookeeper-jute-3.8.6.jar
+ ]]></notes>
+ <packageUrl
regex="true">^pkg:maven/org\.apache\.zookeeper/zookeeper(-jute)?@.*$</packageUrl>
+ <cve>CVE-2026-79993</cve>
+ <cve>CVE-2026-59739</cve>
+ <cve>CVE-2026-59969</cve>
+ </suppress>
</suppressions>
---------------------------------------------------------------------
To unsubscribe, e-mail: [email protected]
For additional commands, e-mail: [email protected]