Components
Vulnerabilities
Pricing
MCP
API
Docs
Sign up
Login
ray 2.54.0 | Vulnerabilities | Sonatype Guide
pypi
ray
2.54.0
ray 2.54.0
Latest
Published
Feb 18, 2026
•
Policy
compliance
pypi Registry
Developer Trust Score
N/A
Recommended Version:
x.y.z
Best
Latest version with 0 known vulnerabilities that meets your policy.
Compare Versions
Overview
Overview
Versions
143
Versions
143
Vulnerabilities
7
Vulnerabilities
7
Dependencies
0
Dependencies
0
Severity
Critical
(0)
High
(5)
Medium
(2)
Low
(0)
CVSS Score
0.0
10.0
EPSS Score
0.0
1.0
Malware
KEV Status
Published
Filter
Sort: Published (Newest first)
6.9
sonatype-2025-000535
github.com/sigstore/sigstore-java (gson) - Stack-based Buffer Overflow [CVE-2025-53864]
affected
Severity
Medium
Published
Feb 13, 2025
7.5
CVE-2024-7254
Any project that parses untrusted Protocol Buffers data containing an arbitrary number of nested groups / series of SGROUP tags can corrupted by exceeding the stack limit i.e. StackOverflow. Parsing nested groups as unknown fields with DiscardUnknownFieldsParser or Java Protobuf Lite parser, or against Protobuf map fields, creates unbounded recursions that can be abused by an attacker.
affected
Severity
8.8
sonatype-2024-1582
ray - Cross-Site Request Forgery (CSRF)
affected
Severity
High
Published
May 3, 2024
7.5
sonatype-2024-1053
ray - Path Traversal
affected
Severity
High
Published
Apr 23, 2024
8.7
sonatype-2023-4396
commons-io - REDOS
affected
Severity
High
Published
Oct 11, 2023
7.8
CVE-2022-4065
A vulnerability was found in cbeust testng 7.5.0/7.6.0/7.6.1/7.7.0. It has been declared as critical. Affected by this vulnerability is the function testngXmlExistsInJar of the file testng-core/src/main/java/org/testng/JarFileUtils.java of the component XML File Parser. The manipulation leads to path traversal. The attack can be launched remotely. Upgrading to version 7.5.1 and 7.7.1 is able to address this issue. The patch is named 9150736cd2c123a6a3b60e6193630859f9f0422b. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-214027.
affected
Severity
High
Published
Nov 21, 2022
6.9
sonatype-2018-0590
org.mozilla:rhino - XML External Entity Reference(XXE)
affected
Severity
Medium
Published
Jul 3, 2019
High
Published
Sep 20, 2024