VulnSea

keras vulnerabilities

CVEs whose affected-version data names the keras package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

16 CVEsRSS

CVE-2026-12570Medium· 5.5
1mo ago

A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function

A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.__getitem__ method in keras/src/saving…

Sunlitkeras · kerasEPSS 0.13%via NVD
CVE-2026-12484High· 7.8
2mo ago

Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data

Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data

Twilightkeras · kerasEPSS 0.39%via OSV
CVE-2026-12482Low· 3.1
2mo ago

Keras: tar extraction permits symlink-based path traversal

Keras: tar extraction permits symlink-based path traversal

Sunlitkeras · kerasEPSS 0.24%via OSV
CVE-2026-12480Medium· 5.5
2mo ago

Keras: HDF5 virtual datasets can disclose local files

Keras: HDF5 virtual datasets can disclose local files

Sunlitkeras · kerasEPSS 0.18%via OSV
CVE-2026-12479Medium· 6.1
3mo ago

Keras: DiskIOStore permits path traversal through crafted layer names

Keras: DiskIOStore permits path traversal through crafted layer names

Sunlitkeras · kerasEPSS 0.38%via OSV
CVE-2026-11816High· 8.1
3mo ago

Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/f…

Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils.py`. The functions `filter_safe_tarinfos()` and `filter_safe_zipinfos()` validate archive …

Twilightkeras · kerasEPSS 0.56%via OSV
CVE-2026-1462High· 7.8
5mo ago

A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`

A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses the secu…

Twilightkeras · kerasEPSS 0.40%via NVD
CVE-2026-1669High· 7.5
7mo ago

Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose sensitive information via a crafted .keras …

Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose sensitive information via a crafted .keras …

Twilightkeras · kerasEPSS 0.31%via NVD
CVE-2026-0897High· 7.5PoC
8mo ago

Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and a c…

Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and a c…

Midnightkeras · kerasEPSS 0.34%via NVD
CVE-2025-12060Critical· 9.8
9mo ago

Keras Directory Traversal Vulnerability

Keras Directory Traversal Vulnerability

Midnightkeras · kerasEPSS 0.59%via OSV
CVE-2025-12058Medium
10mo ago

Keras is vulnerable to arbitrary local file loading and Server-Side Request Forgery

Keras is vulnerable to arbitrary local file loading and Server-Side Request Forgery

Sunlitkeras · kerasEPSS 0.25%via OSV
CVE-2025-9905High
1y ago

The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file i…

The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded.

Twilightkeras · kerasEPSS 0.22%via OSV
CVE-2025-9906High· 7.3
1y ago

Keras is vulnerable to Deserialization of Untrusted Data

Keras is vulnerable to Deserialization of Untrusted Data

Twilightkeras · kerasEPSS 0.20%via OSV
CVE-2025-8747High· 8.8
1y ago

Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality

Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality

Twilightkeras · kerasEPSS 0.12%via OSV
CVE-2025-1550HighPoC
1y ago

Arbitrary Code Execution via Crafted Keras Config for Model Loading

Arbitrary Code Execution via Crafted Keras Config for Model Loading

Midnightkeras · kerasEPSS 2.6%via OSV
CVE-2024-55459Medium
1y ago

keras Path Traversal vulnerability

keras Path Traversal vulnerability

Sunlitkeras · kerasEPSS 0.23%via OSV
keras vulnerabilities (CVEs) · VulnSea