Live data from GitHub and PyPI, updated daily.
Data last fetched: 2026-05-15
10 active CVEs reported via OSV.dev
Ray Path Traversal vulnerability
Ray Missing Authorization vulnerability
Ray has arbitrary code execution via jobs submission API
Ray's New Token Authentication is Disabled By Default
Ray OS Command Injection vulnerability
Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization
Ray is vulnerable to Critical RCE via Safari & Firefox Browsers through DNS Rebinding Attack
Ray dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion)
ray vulnerable to Insertion of Sensitive Information into Log File
Other Machine Learning projects in the Python ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for Ray โ without relying on volunteer maintainers.
Talk to an Expert โ