Skip to content
RayGHSA-gx77-xgc2-4888

Ray's New Token Authentication is Disabled By Default

CriticalCVE-2025-34351 · Published Nov 27, 2025 · updated Sep 10, 2026

Anyscale Ray 2.52.0 contains an insecure default configuration in which token-based authentication for Ray management interfaces (including the dashboard and Jobs API) is disabled unless explicitly enabled by setting RAY_AUTH_MODE=token. In the default unauthenticated state, a remote attacker with network access to these interfaces can submit jobs and execute arbitrary code on the Ray cluster. NOTE: The vendor plans to enable token authentication by default in a future release. They recommend enabling token authentication to protect your cluster from unauthorized access.

GitHub advisory

Affected versions

PackageAffectedFixed in
ray
PyPI
<= 2.52.0No fix yet
Details and references

More Ray advisories

All Ray

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.