ray-project
- Products in analyzed data
- 2
- Catalog vulnerabilities
- 7
Severity across 7 analyzed records
Verify to analyze this security profile
A short verification protects source data and prevents automated AI requests.
en
Severity across 7 analyzed records
A short verification protects source data and prevents automated AI requests.
The GCVE catalog currently lists 7 vulnerability records associated with ray-project.
Among the 7 records analyzed by CyStack, 6 are High or Critical and 1 appear in the CISA KEV catalog for priority remediation.
The list below is based on vulnerabilities that have been viewed and analyzed; it does not represent the complete global vulnerability corpus. Use the product filter to narrow the scope.
CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.
Explore CyStack VulnScan
| CVE | Exploitation status | Fix | Affected product | Published | Severity |
|---|---|---|---|---|---|
CVE-2026-41486Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization | Exploitation statusNot known exploited | FixYes | Affected productray | Published05/08/2026 | SeverityHigh |
CVE-2026-32981Ray Dashboard <= 2.8.0 Path Traversal Leading to Local File Disclosure | Exploitation statusPublic exploit | FixYes | Affected productray | Published03/17/2026 | SeverityHigh |
CVE-2026-27482Ray: Dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion) | Exploitation statusPublic exploit | FixNot confirmed | Affected productray | Published02/21/2026 | SeverityMedium |
CVE-2025-62593Ray is vulnerable to RCE via Safari & Firefox Browsers through DNS Rebinding Attack | Exploitation statusKEV | FixYes | Affected productray | Published11/26/2025 | SeverityCritical |
CVE-2023-6020Ray Static File Local File Include | Exploitation statusNot confirmed | FixNot confirmed | Affected productray-project/ray | Published11/16/2023 | SeverityHigh |
CVE-2023-6019Ray Command Injection in cpu_profile Parameter | Exploitation statusNot confirmed | FixYes | Affected productray-project/ray | Published11/16/2023 | SeverityCritical |
CVE-2023-6021Ray Log File Local File Include | Exploitation statusPublic exploit | FixYes | Affected productray-project/ray | Published11/16/2023 | SeverityHigh |