PatchSiren

ray-project CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Known exploited ray-project CVE published 2026-08-17

CVE-2025-62593

CVE-2025-62593 Ray-Project Ray Code Injection Vulnerability debrief. The vulnerability allows for code injection with a CVSS score of 9.4 and CRITICAL severity. Defenders and security teams responsible for Ray-Project Ray deployments should assess exposure and apply mitigations. Evidence suggests known exploitation in the wild, with potential for code injection and execution. The vulnerability affects Ray [truncated]

HIGH ray-project CVE published 2026-05-08

CVE-2026-41486

Ray Data in versions 2.54.0 through 2.54.x registers custom PyArrow extension types globally. When PyArrow parses a Parquet file schema containing these extension types, the `__arrow_ext_deserialize__` method passes metadata bytes directly to `cloudpickle.loads()`, enabling arbitrary code execution during schema parsing before any row data is read. This deserialization of untrusted data (CWE-502) allows c [truncated]

HIGH ray-project CVE published 2026-03-17

CVE-2026-32981

A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. The vulnerability allows an attacker to access files outside the intended static directory using traversal sequences, resulting in local file disclosure. This issue has a CVSS score of 8.7 and is considered HIGH severity. The CVE was published on March 17, 2026, and last modified on June 30, [truncated]