---
id: CVE-2026-12570
title: >-
  A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of
  service (DoS) attack when loading malicious .keras model files via the
  keras.models.load_model() function
summary: >-
  A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of
  service (DoS) attack when loading malicious .keras model files via the
  keras.models.load_model() function. The H5IOStore.__getitem__ method in
  keras/src/saving…
severity: medium
cvss: 5.5
cvssVector: 'CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H'
cwe:
  - CWE-770
published: '2026-08-10'
updated: '2026-08-10'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-12570'
references:
  - url: >-
      https://github.com/keras-team/keras/commit/4933ea4a5b3fcc24ceacdc276f5bb5dfbd06756c
    label: security@huntr.dev
  - url: 'https://huntr.com/bounties/a064f475-780a-409a-82f7-678512f27ad8'
    label: security@huntr.dev
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2026-12570'
  - url: 'https://github.com/keras-team/keras/pull/22975'
  - url: 'https://github.com/keras-team/keras'
  - url: 'https://github.com/keras-team/keras/releases/tag/v3.15.0'
  - url: 'https://pypi.org/project/keras'
  - url: 'https://github.com/advisories/GHSA-74m6-m3xx-3vmj'
tags:
  - nvd
  - osv
  - pip
ingestedAt: '2026-08-10T07:39:16.916Z'
epss: 0.00128
epssPercentile: 0.02042
aliases:
  - GHSA-74m6-m3xx-3vmj
  - PYSEC-2026-3856
ecosystem: pip
vendor: keras
product: keras
affected:
  - keras < 3.15.0
patched:
  - keras 3.15.0
---

## Overview

A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.__getitem__ method in keras/src/saving/saving_lib.py does not validate the shape or size of datasets, leading to unbounded memory allocation. A specially crafted .keras file can exploit this flaw to trigger an out-of-memory (OOM) condition, causing the process to be terminated (exit code 137). This issue bypasses the fix for CVE-2026-0897, which only addressed a similar vulnerability in KerasFileEditor. The attack vector includes poisoned models from public repositories or malicious model registries, posing a risk to machine learning pipelines that process untrusted models.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.

## Package advisory (CVE-2026-12570)

Affected packages:

- `keras < 3.15.0`

Patched in:

- `keras 3.15.0`

Source: https://osv.dev/vulnerability/GHSA-74m6-m3xx-3vmj
