{"id":1952,"date":"2026-08-20T07:22:21","date_gmt":"2026-08-20T00:22:21","guid":{"rendered":"https:\/\/vncybers.vn\/hieu-ve-dns-rebinding-trong-ray-trinh-duyet-cau-noi-rce\/"},"modified":"2026-08-20T08:43:34","modified_gmt":"2026-08-20T01:43:34","slug":"dns-rebinding-ray-browser-rce-bridge","status":"publish","type":"post","link":"https:\/\/vncybers.vn\/en\/dns-rebinding-ray-browser-rce-bridge\/","title":{"rendered":"Understanding DNS Rebinding in Ray: How the Browser Can Become an RCE Bridge"},"content":{"rendered":"<p><strong>DNS rebinding in Ray<\/strong> is a fresh example of how a weakness in a development tool can move beyond the assumption that it is &#8220;only running internally.&#8221; When CISA added CVE-2025-62593 to its Known Exploited Vulnerabilities catalog, the notable point was not only the severity of the flaw, but also the way a developer&#8217;s browser can be turned into an intermediary that reaches a Ray service running on a local machine or private network.<\/p>\n<p>Ray is an open-source framework used to scale Python workloads, especially in artificial intelligence and machine learning environments. In many development setups, the Ray dashboard or jobs API is started for quick experimentation, task orchestration and cluster visibility. That convenience can make the boundary between an &#8220;internal service&#8221; and a real attack surface much thinner than expected.<\/p>\n<h2>Why CVE-2025-62593 matters<\/h2>\n<p>According to the Ray project advisory, CVE-2025-62593 can lead to remote code execution in a development context when a victim using Firefox or Safari visits a malicious website, or is redirected through malvertising. CISA describes the issue as a code injection vulnerability in Ray that can be exploited through the browser against developers using Ray as a development tool.<\/p>\n<p>The core issue is a defensive assumption that is not strong enough. Some important Ray endpoints, such as the jobs API, were not designed around mandatory authentication for every context. The protection against browser-originated requests relied on identifying User-Agent strings that start with &#8220;Mozilla.&#8221; However, according to the advisory, the Fetch API in Firefox and Safari can allow the User-Agent to be changed in a way that weakens that assumption.<\/p>\n<p style=\"text-align: center;\"><img decoding=\"async\" src=\"https:\/\/vncybers.vn\/wp-content\/uploads\/2026\/08\/ray-dns-rebinding-inline.jpg\" alt=\"Developer working on a computer in a software development environment\" style=\"max-width: 100%; height: auto;\" \/><\/p>\n<h2>How DNS rebinding works<\/h2>\n<p>DNS rebinding is a technique that makes the browser first connect to a domain controlled by the attacker, then changes the DNS resolution of that same domain to an internal address such as localhost or a private network host. From the browser&#8217;s perspective, the request may still appear to belong to the same origin, but the real destination can become an internal service that an external website normally should not reach directly.<\/p>\n<p>When combined with Ray, the risk scenario becomes clearer. A developer running the Ray dashboard on the default port could open a malicious website in the same browser. That site can use DNS rebinding to make the browser send requests to the internal Ray service, then call an API capable of creating jobs or executing commands. The browser becomes a confused intermediary, carrying a request from the Internet into the internal environment.<\/p>\n<h2>Why AI and data environments should pay attention<\/h2>\n<p>In AI development teams, Ray is often connected to notebooks, training pipelines, GPUs, experimental datasets, source-code access tokens and infrastructure credentials. If a Ray cluster or development machine is compromised, the impact does not stop at running a test command. An attacker could scan environment variables, steal API keys, deploy cryptocurrency-mining workloads, or use the system as a foothold into the enterprise network.<\/p>\n<p>The Hacker News has cited earlier reports showing that unpatched Ray versions have previously been targeted in campaigns that turned GPU clusters into cryptocurrency-mining botnets. That history shows that the practical risk around AI tooling is not limited to models and datasets. It also sits in the supporting infrastructure used for development, testing and deployment.<\/p>\n<h2>Practical defensive steps<\/h2>\n<p>The first priority is to upgrade Ray to a patched version, with the advisory noting that version 2.52.0 addresses the issue. Organizations should inventory where Ray is running, especially on engineers&#8217; personal machines, test servers, shared notebooks, GPU clusters and cloud environments where dashboards may be exposed more broadly than intended.<\/p>\n<p>Ray dashboards and administrative APIs should not be exposed directly to the Internet. Where remote access is required, they should sit behind a VPN, an authenticated reverse proxy, network allowlists, or a clear identity-control layer. Teams should also review DNS rebinding protection on routers, proxies, internal DNS resolvers and enterprise browsers.<\/p>\n<p>At the operational level, defenders should review Ray job logs, unusual process history, sudden GPU or CPU spikes, suspicious outbound connections and environment variables containing tokens. For developers, the key principle is not to treat localhost services as automatically safe if the browser can reach them.<\/p>\n<h2>The broader lesson<\/h2>\n<p>CVE-2025-62593 is a reminder of a familiar problem in modern development tooling: internal interfaces, convenient dashboards and unauthenticated APIs can become attack surfaces when browsers, DNS and private networks are combined in unexpected ways. The idea that something is &#8220;only running on a dev machine&#8221; is not enough to reduce risk if that machine regularly browses the web and stores operational secrets.<\/p>\n<p>For organizations scaling AI infrastructure, security is not only about protecting the model after deployment. It starts with developer machines, test clusters, orchestration tools and every supporting API that can run code. When a tool can coordinate compute resources, it should be treated as a sensitive infrastructure component, not as a harmless internal utility.<\/p>\n<p style=\"text-align: right; margin-top: 40px;\"><em><strong>VNCyberS<\/strong> compiled from The Hacker News, CISA and the Ray Project<\/em><\/p>","protected":false},"excerpt":{"rendered":"<p>CVE-2025-62593 in Ray shows how DNS rebinding can turn a developer&#8217;s browser into a bridge to internal services and remote code execution risk.<\/p>","protected":false},"author":2,"featured_media":1950,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":""},"categories":[5],"tags":[639,167,661,354,659,76,660,168,662,153,114],"class_list":["post-1952","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-kien-thuc","tag-ai-security","tag-cisa-kev","tag-cve-2025-62593","tag-developer-security","tag-dns-rebinding","tag-firefox","tag-ray","tag-remote-code-execution","tag-safari","tag-the-hacker-news","tag-vncybers"],"_links":{"self":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/1952","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/comments?post=1952"}],"version-history":[{"count":1,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/1952\/revisions"}],"predecessor-version":[{"id":1953,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/posts\/1952\/revisions\/1953"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/media\/1950"}],"wp:attachment":[{"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/media?parent=1952"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/categories?post=1952"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vncybers.vn\/en\/wp-json\/wp\/v2\/tags?post=1952"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}