{"id":"CGA-j7qp-xmxx-9g7c","modified":"2026-07-17T19:05:34.016614132Z","published":"2026-04-25T13:55:42Z","upstream":["CVE-2026-41486","GHSA-mw35-8rx3-xf9r"],"references":[{"type":"WEB","url":"https://github.com/ray-project/ray/releases/tag/ray-2.55.0"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/41xxx/CVE-2026-41486.json"},{"type":"ADVISORY","url":"https://github.com/ray-project/ray/security/advisories/GHSA-mw35-8rx3-xf9r"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-41486"},{"type":"FIX","url":"https://github.com/ray-project/ray/commit/c02bd31ae31996805868baa446a131a8d304525f"},{"type":"FIX","url":"https://github.com/ray-project/ray/pull/62056"}],"affected":[{"package":{"name":"tritonserver-backend-vllm-cuda-12.9","ecosystem":"Chainguard","purl":"pkg:apk/chainguard/tritonserver-backend-vllm-cuda-12.9?arch=x86_64"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"25.9.0_git20260318-r1"}]}],"ecosystem_specific":{"components":[{"component_purl":"pkg:pypi/ray@2.54.1","latest_event_status":"fixed","latest_event_timestamp":"2026-04-30T00:02:06Z","architecture":"x86_64","component_name":"ray","component_version":"2.54.1","component_type":"python","component_location":"/opt/tritonserver/venv/lib/python3.12/site-packages/ray-2.54.1.dist-info/METADATA"}]},"database_specific":{"source":"https://advisories.cgr.dev/chainguard/v3/osv/CGA-j7qp-xmxx-9g7c.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H"}]}