Ray Vulnerabilities

pip MLOps

AI Threat Alert tracks 19 known vulnerabilities in Ray, 8 rated critical — an AI/ML mlops in the pip ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
64
Risk Score
19
Total CVEs
8
Critical
pip
Ecosystem
Aug 11, 2026
Last CVE
68%
Patch Rate
132d
Avg Time to Patch
43,523 stars 7,928 forks 3,478 issues 620 dependents Last push Aug 16, 2026
View on GitHub
OpenSSF Scorecard 5.8/10

Known Vulnerabilities (19 total, page 1 of 1)

Severity CVE ID Summary CVSS Published
MEDIUM CVE-2026-28707 LLM-on-Ray: local privilege escalation flaw -- Aug 11, 2026 MEDIUM CVE-2026-14548 Ray Translation WP: Subscribers can hijack API token 6.5 Aug 11, 2026 MEDIUM CVE-2026-14549 Ray Enterprise Translation WP plugin: broken access control 4.3 Aug 11, 2026 CRITICAL CVE-2025-4318 amplify-codegen-ui: eval injection enables build-time RCE -- Jul 30, 2026 CRITICAL GHSA-mqhr-6j6h-74p5 Budibase: unauth SSRF leaks stored REST API credentials -- Jul 24, 2026 HIGH CVE-2026-50158 yutu: arbitrary file write via MCP caption-download tool 7.7 Jul 14, 2026 HIGH CVE-2026-57516 Ray: RCE via pickle/torch deserialization in WebDataset 8.8 Jul 1, 2026 MEDIUM CVE-2026-55414 nl-portal: GraphQL SSRF exposes Objecten-API auth token 5.3 Jun 19, 2026 MEDIUM CVE-2026-54683 nl-portal documenten-api: IDOR exposes citizen documents 6.5 Jun 18, 2026 HIGH CVE-2026-32981 Ray Dashboard: unauthenticated path traversal file read 7.5 Mar 17, 2026 HIGH CVE-2026-41486 Ray: Parquet RCE via Arrow extension deserialization -- Apr 24, 2026 CRITICAL CVE-2023-6019 Ray: unauthenticated RCE via dashboard command injection 9.8 Nov 16, 2023 CRITICAL CVE-2023-6020 Ray: unauthenticated LFI exposes entire filesystem 9.3 Nov 16, 2023 CRITICAL CVE-2023-6021 Ray: LFI allows unauthenticated file read 9.3 Nov 16, 2023 MEDIUM CVE-2025-1979 Ray: Redis password exposed via plaintext logging 6.4 Mar 6, 2025 CRITICAL CVE-2023-48022 Ray: unauthenticated RCE via job submission API 9.8 Nov 28, 2023 CRITICAL CVE-2025-62593 ray: Code Injection enables RCE -- Nov 26, 2025 CRITICAL CVE-2025-34351 ray: security flaw enables exploitation -- Nov 27, 2025 MEDIUM CVE-2026-27482 ray: Missing Auth allows unauthenticated access 5.9 Feb 20, 2026

Frequently asked questions

What is Ray?

Ray is an AI/ML mlops tracked by AI Threat Alert for security vulnerabilities in the pip ecosystem.

How many known vulnerabilities does Ray have?

Ray has 19 known CVEs, 8 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is Ray distributed in?

Ray is distributed via the pip ecosystem and categorized as mlops.

Where does the Ray vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of Ray?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor Ray in your stack

Get instant alerts when new vulnerabilities affect Ray. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring