VDB
CVE-2026-27482
CVE-2026-27482
PUBLISHED
CVSS 5.900000095367432 MEDIUM
Ray is an AI compute engine. In versions 2.53.0 and below, thedashboard HTTP server blocks browser-origin POST/PUT but does not cover DELETE, and key DELETE endpoints are unauthenticated by default. If the dashboard/agent is reachable (e.g., --dashboard-host=0.0.0.0), a web page via DNS rebinding or same-network access can issue DELETE requests that shut down Serve or delete jobs without user interaction. This is a drive-by availability impact. The fix for this vulnerability is to update to Ray 2.54.0 or higher.
EPSS 0.06% · 19.1th percentile
Risk Scores
CVSS v3.1
5.900000095367432
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:N/I:L/A:H
EPSS Score
0.06%
19.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| anyscale | ray | 0, 0 |
| ray-project | ray | < 2.54.0, < 2.54.0 |
| PyPI | ray | 0, 0 |
Timeline
- Jan 27, 2026 Fix PR Merged
- Feb 20, 2026 CVE Published
- Feb 21, 2026 EPSS Score
- Feb 21, 2026 PoC Published
- Feb 23, 2026 CVE Updated
- Feb 23, 2026 EPSS Score
- Feb 24, 2026 EPSS Score
- Feb 26, 2026 EPSS Score
- Feb 27, 2026 EPSS Score
- Mar 1, 2026 EPSS Score
- Mar 2, 2026 Security Advisory
- Mar 3, 2026 EPSS Score
References
- https://github.com/ray-project/ray/security/advisories/GHSA-q5fh-2hc8-f6rq url
- https://github.com/ray-project/ray/pull/60526 url
- https://github.com/ray-project/ray/commit/0fda8b824cdc9dc6edd763bb28dfd7d1cc9b02a4 url
- https://github.com/ray-project/ray/releases/tag/ray-2.54.0 url
- https://nvd.nist.gov/vuln/detail/CVE-2026-27482 advisory
- https://github.com/ray-project/ray package