VulnSea

ray has 9 CVEs on record between 2023 and 2026. The median CVSS is 9.3 (critical), with 6 rated critical. 11% have been exploited in the wild, in line with the corpus average.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
11% vs 1% corpus
Median CVSS
9.3
Publish → KEV
(1)
Last 90 days
0 prev 1

Weakness classes

Products

  • ray 9
9
Total CVEs
6
Critical
1
CISA KEV
1
Exploited

ray vulnerabilities

CVEs affecting ray, newest first. Open any entry for full detail, references, and exploit status.

9 CVEsRSS

CVE-2026-41486High
5mo ago

Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization

Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization

Twilightray · rayEPSS 0.47%via OSV
CVE-2026-27482Medium· 5.9
7mo ago

Ray dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion)

Ray dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion)

Sunlitray · rayEPSS 0.27%via OSV
CVE-2025-34351Critical
9mo ago

Ray's New Token Authentication is Disabled By Default

Ray's New Token Authentication is Disabled By Default

Midnightray · rayvia OSV
CVE-2025-62593CriticalCISA KEVPoC
10mo ago

Ray is an AI compute engine

Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient gu…

Hadalray · rayEPSS 17%via NVD
CVE-2025-1979Medium· 6.4
1y ago

ray vulnerable to Insertion of Sensitive Information into Log File

ray vulnerable to Insertion of Sensitive Information into Log File

Sunlitray · rayEPSS 0.19%via OSV
CVE-2023-48022Critical· 9.8PoC
2y ago

Ray has arbitrary code execution via jobs submission API

Ray has arbitrary code execution via jobs submission API

Abyssalray · rayEPSS 84%via OSV
CVE-2023-6019Critical· 9.8PoC
2y ago

Ray OS Command Injection vulnerability

Ray OS Command Injection vulnerability

Abyssalray · rayEPSS 75%via OSV
CVE-2023-6020Critical· 9.3PoC
2y ago

Ray Missing Authorization vulnerability

Ray Missing Authorization vulnerability

Abyssalray · rayEPSS 15%via OSV
CVE-2023-6021Critical· 9.3PoC
2y ago

Ray Path Traversal vulnerability

Ray Path Traversal vulnerability

Abyssalray · rayEPSS 37%via OSV
ray vulnerabilities (CVEs) · VulnSea