VulnSea

ray vulnerabilities

CVEs whose affected-version data names the ray package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

10 CVEsRSS

CVE-2026-41486High
5mo ago

Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization

Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization

Twilightray · rayEPSS 0.47%via OSV
CVE-2026-32981High· 7.5
6mo ago

A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1

A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due to improper validation and sanitization of user-supplied paths in the static file handling mechanism, an attacker can …

Twilightanyscale · rayEPSS 0.93%via NVD
CVE-2026-27482Medium· 5.9
7mo ago

Ray dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion)

Ray dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion)

Sunlitray · rayEPSS 0.27%via OSV
CVE-2025-34351Critical
9mo ago

Ray's New Token Authentication is Disabled By Default

Ray's New Token Authentication is Disabled By Default

Midnightray · rayvia OSV
CVE-2025-62593CriticalCISA KEVPoC
10mo ago

Ray is an AI compute engine

Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient gu…

Hadalray · rayEPSS 17%via NVD
CVE-2025-1979Medium· 6.4
1y ago

ray vulnerable to Insertion of Sensitive Information into Log File

ray vulnerable to Insertion of Sensitive Information into Log File

Sunlitray · rayEPSS 0.19%via OSV
CVE-2023-48022Critical· 9.8PoC
2y ago

Ray has arbitrary code execution via jobs submission API

Ray has arbitrary code execution via jobs submission API

Abyssalray · rayEPSS 84%via OSV
CVE-2023-6019Critical· 9.8PoC
2y ago

Ray OS Command Injection vulnerability

Ray OS Command Injection vulnerability

Abyssalray · rayEPSS 75%via OSV
CVE-2023-6020Critical· 9.3PoC
2y ago

Ray Missing Authorization vulnerability

Ray Missing Authorization vulnerability

Abyssalray · rayEPSS 15%via OSV
CVE-2023-6021Critical· 9.3PoC
2y ago

Ray Path Traversal vulnerability

Ray Path Traversal vulnerability

Abyssalray · rayEPSS 37%via OSV
ray vulnerabilities (CVEs) · VulnSea