Ray Security Update Advisory (CVE-2025-62593)

Ray Security Update Advisory (CVE-2025-62593)

Overview

 

We have released a security update to address a vulnerability in Ray. Affected product users are advised to update to the latest version.
 

 

Affected Products

 

CVE-2025-62593

 

Ray version: 2.less than 52.0

 

 

Resolved Vulnerabilities

 

DNS Rebinding-based Remote Code Execution Vulnerability in Ray (CVE-2025-62593)

 

 

Vulnerability Patches

Vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.

 

CVE-2025-62593

 

Ray Version: 2.52.0

 

 

References

 

[1] Critical RCE Vulnerability against Ray Devs exploitable via Browser (Safari & Firefox) due to DNS Rebinding Attack
https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6v