VendorsAnyscalerayall versions
Vulnerabilities

Anyscale Ray

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

7CVEs
CVE-2023-48022
Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network environment. (Also, within that environment, customers at version 2.52.0 and later can choose to use token authentication.)
Published 2023-11-28 · Modified
9.8EPSS 0.839
CVE-2025-62593
Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack
Published 2025-11-26 · Analyzed
9.4KEVEPSS 0.625
CVE-2023-48023
Anyscale Ray 2.6.3 and 2.8.0 allows /log_proxy SSRF. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for use outside of a strictly controlled network environment
Published 2023-11-28 · Modified
9.1EPSS 0.353
CVE-2026-41486
Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization
Published 2026-05-08 · Analyzed
8.9EPSS 0.007
CVE-2026-57516
Ray < 2.56.0 Unsafe Deserialization RCE via WebDataset Reader
Published 2026-07-01 · Analyzed
8.8EPSS 0.009
CVE-2026-32981
Ray Dashboard <= 2.8.0 Path Traversal Leading to Local File Disclosure
Published 2026-03-17 · Modified
8.7EPSS 0.010
CVE-2026-27482
Ray: Dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion)
Published 2026-02-21 · Analyzed
6.5EPSS 0.004