keras vulnerabilities
CVEs whose affected-version data names the keras package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
16 CVEsRSS
CVE-2026-12570Medium· 5.5A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function
A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.__getitem__ method in keras/src/saving…
CVE-2026-12484High· 7.8Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data
Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data
CVE-2026-12482Low· 3.1Keras: tar extraction permits symlink-based path traversal
Keras: tar extraction permits symlink-based path traversal
CVE-2026-12480Medium· 5.5Keras: HDF5 virtual datasets can disclose local files
Keras: HDF5 virtual datasets can disclose local files
CVE-2026-12479Medium· 6.1Keras: DiskIOStore permits path traversal through crafted layer names
Keras: DiskIOStore permits path traversal through crafted layer names
CVE-2026-11816High· 8.1Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/f…
Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils.py`. The functions `filter_safe_tarinfos()` and `filter_safe_zipinfos()` validate archive …
CVE-2026-1462High· 7.8A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`
A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses the secu…
CVE-2026-1669High· 7.5Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose sensitive information via a crafted .keras …
Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose sensitive information via a crafted .keras …
CVE-2026-0897High· 7.5PoCAllocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and a c…
Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and a c…
CVE-2025-12060Critical· 9.8Keras Directory Traversal Vulnerability
Keras Directory Traversal Vulnerability
CVE-2025-12058MediumKeras is vulnerable to arbitrary local file loading and Server-Side Request Forgery
Keras is vulnerable to arbitrary local file loading and Server-Side Request Forgery
CVE-2025-9905HighThe Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file i…
The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded.
CVE-2025-9906High· 7.3Keras is vulnerable to Deserialization of Untrusted Data
Keras is vulnerable to Deserialization of Untrusted Data
CVE-2025-8747High· 8.8Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality
Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality
CVE-2025-1550HighPoCArbitrary Code Execution via Crafted Keras Config for Model Loading
Arbitrary Code Execution via Crafted Keras Config for Model Loading
CVE-2024-55459Mediumkeras Path Traversal vulnerability
keras Path Traversal vulnerability