Search CVE reports


Toggle filters

1 – 10 of 21 results


CVE-2026-12570

Medium priority
Needs evaluation

A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.__getitem__ method...

1 affected package

keras

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keras Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-9335

Medium priority
Needs evaluation

A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalLinks. The `KerasFileEditor` and `keras.saving.load_weights` functions bypass the...

1 affected package

keras

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keras Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-12484

Medium priority
Needs evaluation

A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle data through the public `keras.layers.TorchModuleWrapper.from_config` method. This method invokes...

1 affected package

keras

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keras Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-12482

Medium priority
Needs evaluation

A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses the `filter_safe_tarinfos` validation in `keras/src/utils/file_utils.py`. Specifically, symlink entries are not...

1 affected package

keras

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keras Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-12481

Medium priority
Needs evaluation

A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` layer. Specifically, the `_raise_for_lambda_deserialization()` function fails to...

1 affected package

keras

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keras Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-12480

Medium priority
Needs evaluation

Keras versions up to and including 3.13.2 are vulnerable to an arbitrary HDF5 file read due to an incomplete fix for CVE-2026-1669. The vulnerability resides in the `H5IOStore._verify_dataset()` and `file_editor.py` methods, which...

1 affected package

keras

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keras Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-12479

Medium priority
Needs evaluation

A path traversal vulnerability exists in keras-team/keras version 3.14.0, specifically in the `DiskIOStore.make` method within the Keras 3 model saving and loading library. This vulnerability arises from the improper handling of...

1 affected package

keras

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keras Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-11816

Medium priority
Needs evaluation

Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils.py`. The functions `filter_safe_tarinfos()` and `filter_safe_zipinfos()` validate...

1 affected package

keras

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keras Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-1462

Medium priority
Needs evaluation

A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses...

1 affected package

keras

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keras Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages

CVE-2026-1669

Medium priority
Needs evaluation

Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose sensitive information via a crafted...

1 affected package

keras

Package 26.04 LTS 24.04 LTS 22.04 LTS 20.04 LTS 18.04 LTS
keras Not in release Not in release Not in release Needs evaluation Needs evaluation
Show less packages