CVE detail
CVE-2026-32981
A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due to improper validation and sanitization of user-supplied paths in the static file handling mechanism, an attacker can use traversal sequences (e.g., ../) to access files outside the intended static directory, resulting in local file disclosure.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 25.6 · diversity 16.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
12 source links · newest first
- https://access.redhat.com/errata/RHSA-2026:42644access.redhat.com
No excerpt available.
Exploitaccess.redhat.comMar 17, 2026, 8:16 PM - https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-32981.jsonsecurity.access.redhat.com
No excerpt available.
Vendor Advisorysecurity.access.redhat.comMar 17, 2026, 8:16 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2448440bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comMar 17, 2026, 8:16 PM - https://access.redhat.com/security/cve/CVE-2026-32981access.redhat.com
No excerpt available.
Exploitaccess.redhat.comMar 17, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:6762access.redhat.com
No excerpt available.
Exploitaccess.redhat.comMar 17, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:6761access.redhat.com
No excerpt available.
Exploitaccess.redhat.comMar 17, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:5809access.redhat.com
No excerpt available.
Exploitaccess.redhat.comMar 17, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:24977access.redhat.com
No excerpt available.
Exploitaccess.redhat.comMar 17, 2026, 8:16 PM - https://access.redhat.com/errata/RHSA-2026:19712access.redhat.com
No excerpt available.
Exploitaccess.redhat.comMar 17, 2026, 8:16 PM - https://www.vulncheck.com/advisories/ray-dashboard-path-traversal-leading-to-local-file-disclosurewww.vulncheck.com
No excerpt available.
Exploitwww.vulncheck.comMar 17, 2026, 8:16 PM - https://packetstorm.news/files/id/215801/packetstorm.news
No excerpt available.
Exploitpacketstorm.newsMar 17, 2026, 8:16 PM - https://github.com/ray-project/raygithub.com
No excerpt available.
Exploitgithub.comMar 17, 2026, 8:16 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-19942CVSS 8.1 · High
The Atarim – AI Agency for WordPress: Edit Pages, Fix Code, Update Plugins, SEO & Client Feedback plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient…
- CVE-2026-73974CVSS 5.5 · Medium
linuxfabrik-lib provides Python modules for database access, caching, shell execution, and API integrations, and Linuxfabrik Monitoring Plugins uses its shared testing helper acro…
- CVE-2026-73973CVSS 5.5 · Medium
Linuxfabrik Monitoring Plugins provides monitoring plugins for Icinga, Nagios, and related systems. Prior to version 7.0.0, check-plugins/logfile/logfile accepted a free-form --fi…
- CVE-2026-52875CVSS 8.4 · High
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.6.0, the perform-scheduled-backup IPC handler in src/ipc/storage.js takes sett…
- CVE-2026-52872CVSS 8.8 · High
Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.5.0, the downloadSubtitleFile utility in src/ipc/downloads.js, reached through…
- CVE-2026-50186CVSS 8.8 · High
4gaBoards is a boards system for realtime project management. Prior to 3.3.8, 4gaBoards allows an authenticated project manager to supply traversal sequences in the filename param…