CVE-2025-34351Critical▾ MidnightRay's New Token Authentication is Disabled By Default
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 52.3 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
Anyscale Ray 2.52.0 contains an insecure default configuration in which token-based authentication for Ray management interfaces (including the dashboard and Jobs API) is disabled unless explicitly enabled by setting RAY_AUTH_MODE=token. In the default unauthenticated state, a remote attacker with network access to these interfaces can submit jobs and execute arbitrary code on the Ray cluster. NOTE: The vendor plans to enable token authentication by default in a future release. They recommend enabling token authentication to protect your cluster from unauthorized access.
ray <= 2.52.0Refer to the advisory for the patched release.
Connected by shared product, vendor, weakness, or advisory.
CVE-2023-48022Critical· 9.8Ray has arbitrary code execution via jobs submission API
CVE-2023-6019Critical· 9.8Ray OS Command Injection vulnerability
CVE-2023-6020Critical· 9.3Ray Missing Authorization vulnerability
CVE-2023-6021Critical· 9.3Ray Path Traversal vulnerability
CVE-2025-62593CriticalRay is an AI compute engine
CVE-2025-1979Medium· 6.4ray vulnerable to Insertion of Sensitive Information into Log File