Ray is an AI compute engine. In versions 2.53.0 and below, thedashboard HTTP server blocks browser-origin POST/PUT but does not cover DELETE, and key DELETE endpoints are unauthenticated by default. If the dashboard/agent is reachable (e.g., --dashboard-host=0.0.0.0), a web page via DNS rebinding or same-network access can issue DELETE requests that shut down Serve or delete jobs without user interaction. This is a drive-by availability impact. The fix for this vulnerability is to update to Ray 2.54.0 or higher.
References
| Link | Resource |
|---|---|
| https://github.com/ray-project/ray/commit/0fda8b824cdc9dc6edd763bb28dfd7d1cc9b02a4 | Patch |
| https://github.com/ray-project/ray/pull/60526 | Issue Tracking Patch |
| https://github.com/ray-project/ray/releases/tag/ray-2.54.0 | Product Release Notes |
| https://github.com/ray-project/ray/security/advisories/GHSA-q5fh-2hc8-f6rq | Exploit Vendor Advisory |
Configurations
History
04 Mar 2026, 18:59
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| References | () https://github.com/ray-project/ray/security/advisories/GHSA-q5fh-2hc8-f6rq - Exploit, Vendor Advisory |
24 Feb 2026, 16:54
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Anyscale
Anyscale ray |
|
| CPE | cpe:2.3:a:anyscale:ray:*:*:*:*:*:*:*:* | |
| References | () https://github.com/ray-project/ray/commit/0fda8b824cdc9dc6edd763bb28dfd7d1cc9b02a4 - Patch | |
| References | () https://github.com/ray-project/ray/pull/60526 - Issue Tracking, Patch | |
| References | () https://github.com/ray-project/ray/releases/tag/ray-2.54.0 - Product, Release Notes | |
| References | () https://github.com/ray-project/ray/security/advisories/GHSA-q5fh-2hc8-f6rq - Vendor Advisory, Exploit |
21 Feb 2026, 10:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-02-21 10:16
Updated : 2026-03-04 18:59
NVD link : CVE-2026-27482
Mitre link : CVE-2026-27482
CVE.ORG link : CVE-2026-27482
JSON object : View
Products Affected
anyscale
- ray
CWE
CWE-396
Declaration of Catch for Generic Exception
