{"id":"CVE-2026-57516","title":"ray: Ray: Remote code execution via unsafe deserialization in WebDataset reader (CVE-2026-57516)","summary":"A flaw was found in Ray. This unsafe deserialization vulnerability in the WebDataset reader allows a remote attacker to achieve arbitrary code execution. By supplying a specially crafted malicious tar archive to the read_webdataset() funct…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cvssSource":"vendor","cwe":"CWE-502","vendor":"Red Hat","product":"Red Hat OpenShift AI (RHOAI)","affected":["ai_inference_server","enterprise_linux_ai_rhel_ai 3","openshift_ai_rhoai","ai_inference_server 3.2","ai_inference_server 3.3"],"patched":["ai_inference_server 3.2","ai_inference_server 3.3"],"published":"2026-07-01","updated":"2026-09-21","sourceUpdated":"2026-09-21T10:35:21+00:00","source":"CSAF","sourceUrl":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-57516.json","references":[{"url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-57516.json"},{"url":"https://access.redhat.com/security/cve/CVE-2026-57516"},{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=2496087"},{"url":"https://www.cve.org/CVERecord?id=CVE-2026-57516"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-57516"},{"url":"https://github.com/ray-project/ray/pull/63469"},{"url":"https://github.com/ray-project/ray/pull/63470"},{"url":"https://github.com/ray-project/ray/releases/tag/ray-2.56.0"},{"url":"https://github.com/ray-project/ray/security/advisories/GHSA-hhrp-gw25-jr43"},{"url":"https://www.vulncheck.com/advisories/ray-unsafe-deserialization-rce-via-webdataset-reader"},{"url":"https://access.redhat.com/errata/RHSA-2026:61627"},{"url":"https://access.redhat.com/errata/RHSA-2026:68699"},{"url":"https://github.com/ray-project/ray/commit/41443a18f9e6403a072de69098a279c23e2d943c"},{"url":"https://github.com/pypa/advisory-database/tree/main/vulns/ray/PYSEC-2026-2273.yaml"},{"url":"https://github.com/ray-project/ray"}],"tags":["csaf","vex","red-hat","osv","pip"],"epss":0.00858,"epssPercentile":0.56441,"aliases":["GHSA-hhrp-gw25-jr43","PYSEC-2026-2273"],"ecosystem":"pip","ingestedAt":"2026-07-13T18:58:08.788Z","slug":"CVE-2026-57516","body":"## Overview\n\nA flaw was found in Ray. This unsafe deserialization vulnerability in the WebDataset reader allows a remote attacker to achieve arbitrary code execution. By supplying a specially crafted malicious tar archive to the read_webdataset() function, an attacker can trigger the unconditional deserialization of .pkl/.pickle or .pt/.pth entries, leading to the execution of arbitrary code within Ray remote workers.\n\n## Vendor advisories\n\n- **RHSA-2026:61627** · Red Hat · fixed in: Red Hat AI Inference Server 3.2 · released 2026-08-31 · [advisory](https://access.redhat.com/errata/RHSA-2026:61627)\n- **RHSA-2026:68699** · Red Hat · fixed in: Red Hat AI Inference Server 3.3 · released 2026-09-17 · [advisory](https://access.redhat.com/errata/RHSA-2026:68699)\n- **Red Hat VEX** · Important · affected: Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI) · no fix planned: Red Hat AI Inference Server, Red Hat Enterprise Linux AI (RHEL AI) 3, Red Hat OpenShift AI (RHOAI) · updated 2026-09-21 · [vex](https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-57516.json)\n\n**ray: Ray: Remote code execution via unsafe deserialization in WebDataset reader** — rated Important by Red Hat. Released 2026-07-01, updated 2026-09-21.\n\nAffected:\n\n- Red Hat AI Inference Server\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n\nFixed:\n\n- Red Hat AI Inference Server 3.2\n- Red Hat AI Inference Server 3.3\n\nNo fix planned:\n\n- Red Hat AI Inference Server\n- Red Hat Enterprise Linux AI (RHEL AI) 3\n- Red Hat OpenShift AI (RHOAI)\n\nNot affected:\n\n- Red Hat OpenShift AI (RHOAI)\n\n## Remediation\n\nFor more information visit https://access.redhat.com/errata/RHSA-2026:61627 https://access.redhat.com/errata/RHSA-2026:61627\nFor more information visit https://access.redhat.com/errata/RHSA-2026:68699 https://access.redhat.com/errata/RHSA-2026:68699\n\nWorkarounds / mitigations:\n\n- To mitigate this issue, restrict the processing of untrusted tar archives by the Ray WebDataset reader. Ensure that only verified and trusted data sources are supplied to the `read_webdataset()` function. Implement strict access controls and input validation for data ingestion pipelines that interact with Ray's WebDataset reader to prevent the introduction of malicious archives.\n\n## Package advisory (CVE-2026-57516)\n\nAffected packages:\n\n- `ray < 2.56.0`\n\nPatched in:\n\n- `ray 2.56.0`\n\nSource: https://osv.dev/vulnerability/GHSA-hhrp-gw25-jr43","depth":"twilight","depthScore":49,"depthScoreParts":{"impact":48.4,"likelihood":0.2,"exploitation":0,"ransomware":0},"changes":[{"seq":201824,"id":"CVE-2026-57516","ts":1789399727523,"field":"cvss","old":null,"new":"8.8"},{"seq":201823,"id":"CVE-2026-57516","ts":1789399727523,"field":"severity","old":"none","new":"high"},{"seq":200554,"id":"CVE-2026-57516","ts":1789397385464,"field":"cvss","old":"8.8","new":null},{"seq":200553,"id":"CVE-2026-57516","ts":1789397385464,"field":"severity","old":"high","new":"none"},{"seq":198471,"id":"CVE-2026-57516","ts":1789391969453,"field":"cvss","old":null,"new":"8.8"},{"seq":198470,"id":"CVE-2026-57516","ts":1789391969453,"field":"severity","old":"none","new":"high"},{"seq":196264,"id":"CVE-2026-57516","ts":1789383588464,"field":"cvss","old":"8.8","new":null},{"seq":196263,"id":"CVE-2026-57516","ts":1789383588464,"field":"severity","old":"high","new":"none"},{"seq":195193,"id":"CVE-2026-57516","ts":1789380477663,"field":"cvss","old":null,"new":"8.8"},{"seq":195192,"id":"CVE-2026-57516","ts":1789380477663,"field":"severity","old":"none","new":"high"},{"seq":193980,"id":"CVE-2026-57516","ts":1789378528290,"field":"cvss","old":"8.8","new":null},{"seq":193979,"id":"CVE-2026-57516","ts":1789378528290,"field":"severity","old":"high","new":"none"},{"seq":192767,"id":"CVE-2026-57516","ts":1789376408031,"field":"cvss","old":null,"new":"8.8"},{"seq":192766,"id":"CVE-2026-57516","ts":1789376408031,"field":"severity","old":"none","new":"high"},{"seq":191554,"id":"CVE-2026-57516","ts":1789373430231,"field":"cvss","old":"8.8","new":null},{"seq":191553,"id":"CVE-2026-57516","ts":1789373430231,"field":"severity","old":"high","new":"none"},{"seq":190339,"id":"CVE-2026-57516","ts":1789369300964,"field":"cvss","old":null,"new":"8.8"},{"seq":190338,"id":"CVE-2026-57516","ts":1789369300964,"field":"severity","old":"none","new":"high"},{"seq":189126,"id":"CVE-2026-57516","ts":1789368268336,"field":"cvss","old":"8.8","new":null},{"seq":189125,"id":"CVE-2026-57516","ts":1789368268336,"field":"severity","old":"high","new":"none"},{"seq":187909,"id":"CVE-2026-57516","ts":1789365144023,"field":"cvss","old":null,"new":"8.8"},{"seq":187908,"id":"CVE-2026-57516","ts":1789365144023,"field":"severity","old":"none","new":"high"},{"seq":186696,"id":"CVE-2026-57516","ts":1789363281791,"field":"cvss","old":"8.8","new":null},{"seq":186695,"id":"CVE-2026-57516","ts":1789363281791,"field":"severity","old":"high","new":"none"},{"seq":185482,"id":"CVE-2026-57516","ts":1789361102108,"field":"cvss","old":null,"new":"8.8"},{"seq":185481,"id":"CVE-2026-57516","ts":1789361102108,"field":"severity","old":"none","new":"high"},{"seq":184269,"id":"CVE-2026-57516","ts":1789358157649,"field":"cvss","old":"8.8","new":null},{"seq":184268,"id":"CVE-2026-57516","ts":1789358157649,"field":"severity","old":"high","new":"none"},{"seq":182520,"id":"CVE-2026-57516","ts":1789354223149,"field":"cvss","old":null,"new":"8.8"},{"seq":182519,"id":"CVE-2026-57516","ts":1789354223149,"field":"severity","old":"none","new":"high"},{"seq":181313,"id":"CVE-2026-57516","ts":1789353129393,"field":"cvss","old":"8.8","new":null},{"seq":181312,"id":"CVE-2026-57516","ts":1789353129393,"field":"severity","old":"high","new":"none"},{"seq":180106,"id":"CVE-2026-57516","ts":1789350169789,"field":"cvss","old":null,"new":"8.8"},{"seq":180105,"id":"CVE-2026-57516","ts":1789350169789,"field":"severity","old":"none","new":"high"},{"seq":178899,"id":"CVE-2026-57516","ts":1789348102794,"field":"cvss","old":"8.8","new":null},{"seq":178898,"id":"CVE-2026-57516","ts":1789348102794,"field":"severity","old":"high","new":"none"},{"seq":177692,"id":"CVE-2026-57516","ts":1789346278287,"field":"cvss","old":null,"new":"8.8"},{"seq":177691,"id":"CVE-2026-57516","ts":1789346278287,"field":"severity","old":"none","new":"high"},{"seq":176485,"id":"CVE-2026-57516","ts":1789343019825,"field":"cvss","old":"8.8","new":null},{"seq":176484,"id":"CVE-2026-57516","ts":1789343019825,"field":"severity","old":"high","new":"none"},{"seq":174602,"id":"CVE-2026-57516","ts":1789334772272,"field":"cvss","old":null,"new":"8.8"},{"seq":174601,"id":"CVE-2026-57516","ts":1789334772272,"field":"severity","old":"none","new":"high"},{"seq":173397,"id":"CVE-2026-57516","ts":1789333515911,"field":"cvss","old":"8.8","new":null},{"seq":173396,"id":"CVE-2026-57516","ts":1789333515911,"field":"severity","old":"high","new":"none"},{"seq":172211,"id":"CVE-2026-57516","ts":1789331018742,"field":"cvss","old":null,"new":"8.8"},{"seq":172210,"id":"CVE-2026-57516","ts":1789331018742,"field":"severity","old":"none","new":"high"},{"seq":171025,"id":"CVE-2026-57516","ts":1789328623107,"field":"cvss","old":"8.8","new":null},{"seq":171024,"id":"CVE-2026-57516","ts":1789328623107,"field":"severity","old":"high","new":"none"},{"seq":169820,"id":"CVE-2026-57516","ts":1789327051673,"field":"cvss","old":null,"new":"8.8"},{"seq":169819,"id":"CVE-2026-57516","ts":1789327051673,"field":"severity","old":"none","new":"high"}]}