Skip to main content

Vendor/product archive

anyscale / ray CVEs

Beta · best-effort

7 CVEs tagged to anyscale / ray3 Critical, 3 High, 1 Medium, 0 Low, 0 Unrated.

CVE-2026-57516

Published Jul 1, 2026

Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to achieve remote code execution by supplying a malicious tar a…

CVSS 8.6 · High
evidence mentions
5
Buzz score
24.4
Vendor/product tagsBeta · best-effort

CVE-2026-41486

Published May 8, 2026

Ray is an AI compute engine. From version 2.54.0 to before version 2.55.0, Ray Data registers custom Arrow extension types (ray.data.arrow_tensor, ray.data.arrow_tensor_v2, ray.da…

CVSS 8.9 · High
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2026-32981

Published Mar 17, 2026

A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due to improper validation and sanitization of user-supplied pat…

CVSS 8.7 · High
evidence mentions
12
Buzz score
41.6
Vendor/product tagsBeta · best-effort

CVE-2026-27482

Published Feb 21, 2026

Ray is an AI compute engine. In versions 2.53.0 and below, thedashboard HTTP server blocks browser-origin POST/PUT but does not cover DELETE, and key DELETE endpoints are unauthen…

CVSS 5.9 · Medium
evidence mentions
4
Buzz score
21.1
Vendor/product tagsBeta · best-effort

CVE-2025-62593

Published Nov 26, 2025

Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox a…

CVSS 9.4 · Critical
evidence mentions
7
Buzz score
65.8
KEV listed
Vendor/product tagsBeta · best-effort

CVE-2023-48023

Published Nov 28, 2023

Anyscale Ray 2.6.3 and 2.8.0 allows /log_proxy SSRF. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for…

CVSS 9.1 · Critical
evidence mentions
2
Buzz score
17.5
Vendor/product tagsBeta · best-effort

CVE-2023-48022

Published Nov 28, 2023

Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the vendor's position is that this report is irrelevant because R…

CVSS 9.8 · Critical
evidence mentions
7
Buzz score
33.8
Vendor/product tagsBeta · best-effort
Showing 1-7 of 7 CVEsPage 1 of 1