Anyscale's vulnerability profile centers on Ray, a distributed computing framework that enables large-scale machine-learning and data-processing workloads, with disclosures spanning network-interaction and code-handling weakness classes. The recurring exposure patterns reflect the framework's broad code-execution and serialization surface: server-side request forgery, deserialization of untrusted data, code injection, path traversal, and overly broad exception handling, each of which carries risk in a system designed to execute distributed tasks. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Anyscale over time
Signals from CVEs in this vendor scope (6 CVEs).
6 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-48022CRITICAL Anyscale Ray 2.6.3 and 2.8.0 allows a remote attacker to execute arbitrary code via the job submission API. NOTE: the vendor's position is that this report is irrelevant because Ra | Nov 28, 2023 | 9.8 | 88 | NO | YES |
CVE-2023-48023CRITICAL Anyscale Ray 2.6.3 and 2.8.0 allows /log_proxy SSRF. NOTE: the vendor's position is that this report is irrelevant because Ray, as stated in its documentation, is not intended for | Nov 28, 2023 | 9.1 | 59 | NO | YES |
CVE-2026-57516HIGH Ray prior to 2.56.0 contains an unsafe deserialization vulnerability in the WebDataset reader that allows attackers to achieve remote code execution by supplying a malicious tar ar | Jul 1, 2026 | 8.8 | 38 | NO | NO |
CVE-2026-41486HIGH Ray is an AI compute engine. From version 2.54.0 to before version 2.55.0, Ray Data registers custom Arrow extension types (ray.data.arrow_tensor, ray.data.arrow_tensor_v2, ray.dat | May 8, 2026 | 8.8 | 32 | NO | NO |
CVE-2026-32981HIGH A path traversal vulnerability was identified in Ray Dashboard (default port 8265) in Ray versions prior to 2.8.1. Due to improper validation and sanitization of user-supplied path | Mar 17, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-27482MEDIUM Ray is an AI compute engine. In versions 2.53.0 and below, thedashboard HTTP server blocks browser-origin POST/PUT but does not cover DELETE, and key DELETE endpoints are unauthent | Feb 21, 2026 | 6.5 | 23 | NO | NO |
Signals from CVEs in this vendor scope (6 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Anyscale.
Media articles that mention a CVE ID that affects a product developed by Anyscale — matched by CVE ID, not by vendor name.