{"id":"CVE-2026-12570","title":"A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function","summary":"A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.__getitem__ method in keras/src/saving…","severity":"medium","cvss":5.5,"cvssVector":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H","cwe":["CWE-770"],"published":"2026-08-10","updated":"2026-08-10","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-12570","references":[{"url":"https://github.com/keras-team/keras/commit/4933ea4a5b3fcc24ceacdc276f5bb5dfbd06756c","label":"security@huntr.dev"},{"url":"https://huntr.com/bounties/a064f475-780a-409a-82f7-678512f27ad8","label":"security@huntr.dev"},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12570"},{"url":"https://github.com/keras-team/keras/pull/22975"},{"url":"https://github.com/keras-team/keras"},{"url":"https://github.com/keras-team/keras/releases/tag/v3.15.0"},{"url":"https://pypi.org/project/keras"},{"url":"https://github.com/advisories/GHSA-74m6-m3xx-3vmj"}],"tags":["nvd","osv","pip"],"ingestedAt":"2026-08-10T07:39:16.916Z","epss":0.00128,"epssPercentile":0.02786,"aliases":["GHSA-74m6-m3xx-3vmj","PYSEC-2026-3856"],"ecosystem":"pip","vendor":"keras","product":"keras","affected":["keras < 3.15.0"],"patched":["keras 3.15.0"],"slug":"CVE-2026-12570","body":"## Overview\n\nA vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.__getitem__ method in keras/src/saving/saving_lib.py does not validate the shape or size of datasets, leading to unbounded memory allocation. A specially crafted .keras file can exploit this flaw to trigger an out-of-memory (OOM) condition, causing the process to be terminated (exit code 137). This issue bypasses the fix for CVE-2026-0897, which only addressed a similar vulnerability in KerasFileEditor. The attack vector includes poisoned models from public repositories or malicious model registries, posing a risk to machine learning pipelines that process untrusted models.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.\n\n## Package advisory (CVE-2026-12570)\n\nAffected packages:\n\n- `keras < 3.15.0`\n\nPatched in:\n\n- `keras 3.15.0`\n\nSource: https://osv.dev/vulnerability/GHSA-74m6-m3xx-3vmj","depth":"sunlit","depthScore":30,"depthScoreParts":{"impact":30.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}