Ray Security Update Advisory (CVE-2025-62593)
Overview
We have released a security update to address a vulnerability in Ray. Affected product users are advised to update to the latest version.
Affected Products
CVE-2025-62593
Ray version: 2.less than 52.0
Resolved Vulnerabilities
DNS Rebinding-based Remote Code Execution Vulnerability in Ray (CVE-2025-62593)
Vulnerability Patches
Vulnerability Patches have been made available in the latest update. Please follow the instructions on the Referenced Sites to update to the latest Vulnerability Patches version.
CVE-2025-62593
Ray Version: 2.52.0
References
[1] Critical RCE Vulnerability against Ray Devs exploitable via Browser (Safari & Firefox) due to DNS Rebinding Attack
https://github.com/ray-project/ray/security/advisories/GHSA-q279-jhrf-cc6v