Skip to content
RequestGuard Vulnerabilities
Pricing

ray

Ray provides a simple, universal API for building distributed applications.

PyPI latest 2.58.0 Apache 2.0

Evidence path

Version, exploitation, severity

RequestGuard keeps these facts separate. A KEV match refers to a CVE, while OSV supplies the package and version match.

1

Latest version

2.58.0

No matching published advisory returned

2

Known exploitation

No KEV match

Checked by exact CVE identifier

3

Highest advisory severity

Critical

11 active advisories

Check an exact version

The registry confirms the version, then OSV checks advisories for that exact value.

Published records

Advisories

11

Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization

Affected range

ECOSYSTEM: introduced 2.49.0; fixed 2.55.0ECOSYSTEM: introduced 0; last affected 2.54.0

Fixed versions: 2.55.0

Ray: Arbitrary code execution via ray.data.read_webdataset default decoder: pickle.loads(value) and torch.load(weights_only=False)

Affected range

ECOSYSTEM: introduced 0; fixed 2.56.0

Fixed versions: 2.56.0

ray vulnerable to Insertion of Sensitive Information into Log File

Affected range

ECOSYSTEM: introduced 0; fixed 2.43.0GIT: introduced 0; fixed 64a2e4010522d60b90c389634f24df77b603d85d

Fixed versions: 2.43.0, 64a2e4010522d60b90c389634f24df77b603d85d