← what I check

EXPOSURE Ray
SEVERITY CRITICAL
PROBE GET :8265/api/jobs/

CRITICAL

Is your Ray exposed?

Open dashboard: unauthenticated job submission is remote code execution on your cluster.

Scan a host you own → Fix card

Why it matters

Your Ray dashboard and Jobs API answer anyone without a password. The Jobs API lets a stranger submit a job — and a Ray job is arbitrary code running on your cluster. This is unauthenticated remote code execution, and exposed Ray clusters are actively hijacked for cryptomining and data theft.

How common is it?

A published population estimate for Ray is still collecting. See the census methodology.

Counts are population-level, from third-party indexes and my own honeypots. I never scan the internet and this page makes no claim about any specific host.

Fix it

The full walkthrough lives on the fix card, kept current in one place:

Full fix card: ray-exposed →