Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-q5fh-2hc8-f6rq | Ray dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion) |
Thu, 26 Feb 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 24 Feb 2026 17:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Anyscale
Anyscale ray |
|
| CPEs | cpe:2.3:a:anyscale:ray:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Anyscale
Anyscale ray |
Mon, 23 Feb 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Ray Project
Ray Project ray |
|
| Vendors & Products |
Ray Project
Ray Project ray |
Sat, 21 Feb 2026 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Ray is an AI compute engine. In versions 2.53.0 and below, thedashboard HTTP server blocks browser-origin POST/PUT but does not cover DELETE, and key DELETE endpoints are unauthenticated by default. If the dashboard/agent is reachable (e.g., --dashboard-host=0.0.0.0), a web page via DNS rebinding or same-network access can issue DELETE requests that shut down Serve or delete jobs without user interaction. This is a drive-by availability impact. The fix for this vulnerability is to update to Ray 2.54.0 or higher. | |
| Title | Ray: Dashboard DELETE endpoints allow unauthenticated browser-triggered DoS (Serve shutdown / job deletion) | |
| Weaknesses | CWE-396 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2026-02-24T18:52:03.874Z
Reserved: 2026-02-19T19:46:03.540Z
Link: CVE-2026-27482
Updated: 2026-02-24T18:51:56.304Z
Status : Analyzed
Published: 2026-02-21T10:16:12.380
Modified: 2026-03-04T18:59:13.370
Link: CVE-2026-27482
No data.
OpenCVE Enrichment
Updated: 2026-04-17T17:00:10Z
Github GHSA