CISA gives federal agencies 3 days to patch a critical Ray RCE bug

CISA's Binding Operational Directive 26-04 orders US federal civilian agencies to patch a critical remote code execution flaw in Ray, the distributed computing framework widely used for scaling Python and machine learning workloads, within three days instead of the usual 14. The bug, CVE-2025-62593, carries a CVSS score of 9.4.
The flaw exploits how Firefox and Safari handle the Fetch API to bypass Ray's User-Agent header check. An attacker who gets a developer to visit a malicious or compromised page can use DNS rebinding to reach a Ray instance listening on localhost or inside a private network, turning the browser into what the researchers who found it call a "confused deputy" that executes attacker-supplied code on the victim's machine or network.
Ray is maintained under the Linux Foundation's PyTorch Foundation, with over 237 million total downloads and 7 million weekly downloads. That footprint is exactly why a three-day directive is notable: CISA hasn't said whether it's seen ransomware groups actively exploiting this specific bug, but the compressed timeline signals it isn't treating the risk as theoretical.
Ray 2.52.0 fixes the underlying issue and adds optional token-based authentication, though that authentication is off by default. If your Ray cluster is reachable from a machine that also browses the web, either through a dev box or a jump host, upgrading alone isn't enough. Turn on token auth explicitly, and keep Ray's dashboard and client ports off any network path that touches the open internet, the same isolation guidance the project has given since well before this CVE.