CVE-2026-41486General(anyscale / ray)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Ray is an AI compute engine. From version 2.54.0 to before version 2.55.0, Ray Data registers custom Arrow extension types (ray.data.arrow_tensor, ray.data.arrow_tensor_v2, ray.data.arrow_variable_shaped_tensor) globally in PyArrow. When PyArrow reads a Parquet file containing one of these extension types, it calls __arrow_ext_deserialize__ on the field's metadata bytes. Ray's implementation passes these bytes directly to cloudpickle.loads(), achieving arbitrary code execution during schema parsing, before any row data is read. This issue has been patched in version 2.55.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-94CWE-502

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • ray

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
ray

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-05-09: 1Technical Details · 2026-05-09: 105-09
Signal classification1 categories
General
1100.0%
Referenced assets2 URLs
By indicator
Full discourse1 post
  • CVE@CVEnew
    General

    CVE-2026-41486 Ray is an AI compute engine. From version 2.54.0 to before version 2.55.0, Ray Data registers custom Arrow extension types (http://ray.data.arrow_tensor, http://ray.data.arrow_tens… https://www.cve.org/CVERecord?id=CVE-2026-41486

    Post summary

    The text notes the existence of CVE-2026-41486 in Ray Data, mentioning a version range and custom Arrow extension types, but lacks deeper technical details, exploitation info, or mitigation guidance.

    0000098
    57.5K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appanyscaleray2.54.0--

Explore more