Skip to content

Anyscale security advisories

11 advisories across Ray

Company profile
DateAdvisory
Jul 24Ray: Arbitrary code execution via ray.data.read_webdataset default decoder: pickle.loads(value) and torch.load(weights_only=False)
CVE-2026-57516High8.8fixed in 2.56.0
Apr 24Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization
CVE-2026-41486Highfixed in 2.55.0
Mar 17Ray Dashboard is vulnerable to path traversal through its static file handling mechanism
CVE-2026-32981High7.5fixed in 2.8.1
Feb 20Ray dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion)
CVE-2026-27482Medium5.9fixed in 2.54.0
Nov 272025Ray's New Token Authentication is Disabled By Default
CVE-2025-34351Criticalno fix yet
Nov 262025Ray is vulnerable to Critical RCE via Safari & Firefox Browsers through DNS Rebinding Attack
CVE-2025-62593Criticalfixed in 2.52.0
Mar 62025ray vulnerable to Insertion of Sensitive Information into Log File
CVE-2025-1979Medium6.4fixed in 2.43.0
Nov 282023Ray has arbitrary code execution via jobs submission API
CVE-2023-48022Critical9.8no fix yet
Nov 162023Ray Missing Authorization vulnerability
CVE-2023-6020Critical9.3fixed in 2.8.1
Nov 162023Ray Path Traversal vulnerability
CVE-2023-6021Critical9.3fixed in 2.8.1
Nov 162023Ray OS Command Injection vulnerability
CVE-2023-6019Critical9.8fixed in 2.8.1
About Anyscale

Elsewhere on fru.dev: Paydays · Releases · Repos · TechConf

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.