HIGH
Anyscale, Inc
CVE published 2026-07-01
CVE-2026-57516
CVE-2026-57516 debrief: Ray < 2.56.0 Unsafe Deserialization RCE via WebDataset Reader. The CVE record was published on 2026-07-01T16:36:55.765Z and has not been modified since then. This vulnerability allows attackers to achieve remote code execution by supplying a malicious tar archive to the read_webdataset() function. The _default_decoder() function in webdataset_datasource.py unconditionally calls pic [truncated]