Skip to content

Google security advisories

453 advisories across TensorFlow, Keras

Company profile
DateAdvisory
Aug 10Keras model loading is vulnerable to denial of service through HDF5 shape bombs
CVE-2026-12570KerasMedium5.5fixed in 3.15.0
Aug 2Keras: HDF5 links can disclose local file contents
CVE-2026-9335KerasMedium6.5fixed in 3.12.3, 3.15.0
Jul 19Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data
CVE-2026-12484KerasHigh7.8fixed in 3.12.3, 3.15.0
Jul 14Keras: tar extraction permits symlink-based path traversal
CVE-2026-12482KerasLow3.1fixed in 3.12.3, 3.15.0
Jul 3Keras: Lambda deserialization can bypass safe mode and execute code
CVE-2026-12481KerasHigh8.8fixed in 3.12.3, 3.15.0
Jul 1Keras: HDF5 virtual datasets can disclose local files
CVE-2026-12480KerasMedium5.5fixed in 3.12.3, 3.15.0
Jun 22Keras: DiskIOStore permits path traversal through crafted layer names
CVE-2026-12479KerasMedium6.1fixed in 3.12.3, 3.15.0
Jun 11Keras archive extraction utilities allow path traversal and arbitrary file writes
CVE-2026-11816KerasHigh8.1fixed in 3.14.0
May 6Keras vulnerable to DoS via Malicious .keras Model (HDF5 Shape Bomb Causes Petabyte Allocation in KerasFileEditor)
CVE-2026-0897KerasHighfixed in 3.12.1, 3.13.2
Apr 13Keras has an untrusted deserialization vulnerability
CVE-2026-1462KerasHigh8.8fixed in 3.13.2
Feb 18Keras has a Local File Disclosure via HDF5 External Storage During Keras Weight Loading
CVE-2026-1669KerasHigh7.1fixed in 3.12.1, 3.13.2
Dec 22025Keras Directory Traversal Vulnerability
CVE-2025-12060KerasHigh9.8fixed in 3.12.0
Oct 292025Keras is vulnerable to arbitrary local file loading and Server-Side Request Forgery
CVE-2025-12058KerasMediumfixed in 3.12.0
Oct 172025Keras framework vulnerable to deserialization of untrusted data
CVE-2025-49655KerasCritical9.8fixed in 3.11.3
Sep 192025The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded.
CVE-2025-9905KerasHighfixed in 3.11.3
Sep 192025Keras is vulnerable to Deserialization of Untrusted Data
CVE-2025-9906KerasHigh7.3fixed in 3.11.0
Aug 122025Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality
CVE-2025-8747KerasHigh8.8fixed in 3.11.0
Mar 112025Arbitrary Code Execution via Crafted Keras Config for Model Loading
CVE-2025-1550KerasHighfixed in 3.9.0
Jan 82025keras Path Traversal vulnerability
CVE-2024-55459KerasMediumno fix yet
Jul 302024TensorFlow has segfault in array_ops.upper_bound
CVE-2023-33976TensorFlowHigh7.5fixed in 2.12.1
Apr 162024Keras code injection vulnerability
CVE-2024-3660KerasCritical9.8fixed in 2.13.1rc0
Mar 272023TensorFlow Denial of Service vulnerability
CVE-2023-25661TensorFlowMedium6.5fixed in 2.11.1
Mar 242023TensorFlow vulnerable to Out-of-Bounds Read in DynamicStitch
CVE-2023-25659TensorFlowHigh7.5fixed in 2.11.1
Mar 242023TensorFlow vulnerable to seg fault in `tf.raw_ops.Print`
CVE-2023-25660TensorFlowHigh7.5fixed in 2.11.1
Mar 242023TensorFlow vulnerable to integer overflow in EditDistance
CVE-2023-25662TensorFlowHigh7.5fixed in 2.11.1
Mar 242023TensorFlow has Null Pointer Error in TensorArrayConcatV2
CVE-2023-25663TensorFlowHigh7.5fixed in 2.11.1
Mar 242023TensorFlow has Heap-buffer-overflow in AvgPoolGrad
CVE-2023-25664TensorFlowHigh7.5fixed in 2.11.1
Mar 242023TensorFlow has Null Pointer Error in SparseSparseMaximum
CVE-2023-25665TensorFlowHigh7.5fixed in 2.11.1
Mar 242023TensorFlow has Floating Point Exception in AudioSpectrogram
CVE-2023-25666TensorFlowHigh7.5fixed in 2.11.1
Mar 242023TensorFlow vulnerable to segfault when opening multiframe gif
CVE-2023-25667TensorFlowMedium6.5fixed in 2.11.1
Mar 242023TensorFlow has a heap out-of-buffer read vulnerability in the QuantizeAndDequantize operation
CVE-2023-25668TensorFlowCritical9.8fixed in 2.11.1
Mar 242023TensorFlow has Floating Point Exception in AvgPoolGrad with XLA
CVE-2023-25669TensorFlowHigh7.5fixed in 2.11.1
Mar 242023TensorFlow has Null Pointer Error in QuantizedMatMulWithBiasAndDequantize
CVE-2023-25670TensorFlowHigh7.5fixed in 2.11.1
Mar 242023TensorFlow has segmentation fault in tfg-translate
CVE-2023-25671TensorFlowHigh7.5fixed in 2.11.1
Mar 242023TensorFlow has Null Pointer Error in LookupTableImportV2
CVE-2023-25672TensorFlowHigh7.5fixed in 2.11.1
Mar 242023TensorFlow has Floating Point Exception in TensorListSplit with XLA
CVE-2023-25673TensorFlowHigh7.5fixed in 2.11.1
Mar 242023TensorFlow has Null Pointer Error in RandomShuffle with XLA enable
CVE-2023-25674TensorFlowHigh7.5fixed in 2.11.1
Mar 242023TensorFlow has Segfault in Bincount with XLA
CVE-2023-25675TensorFlowHigh7.5fixed in 2.11.1
Mar 242023TensorFlow has null dereference on ParallelConcat with XLA
CVE-2023-25676TensorFlowHigh7.5fixed in 2.11.1
Mar 242023TensorFlow has double free in Fractional(Max/Avg)Pool
CVE-2023-25801TensorFlowHigh8.0fixed in 2.11.1
Mar 242023TensorFlow has Floating Point Exception in TFLite in conv kernel
CVE-2023-27579TensorFlowHigh7.5fixed in 2.11.1
Mar 242023TensorFlow vulnerable to Out-of-Bounds Read in GRUBlockCellGrad
CVE-2023-25658TensorFlowHigh7.5fixed in 2.11.1
Nov 222022Tensorflow vulnerable to Out-of-Bounds Read
CVE-2022-41880TensorFlowMedium6.8fixed in 2.8.4, 2.9.3, 2.10.1
Nov 212022`CHECK` failure in `SobolSample` via missing validation
GHSA-cqvq-fvhr-v6hcTensorFlowLowfixed in 2.8.4, 2.9.3, 2.10.1
Nov 212022`CHECK` fail in `TensorListScatter` and `TensorListScatterV2` in eager mode
GHSA-xf83-q765-xm6mTensorFlowLowfixed in 2.8.4, 2.9.3, 2.10.1
Nov 212022Invalid char to bool conversion when printing a tensor
CVE-2022-41911TensorFlowMedium4.8fixed in 2.8.4, 2.9.3, 2.10.1
Nov 212022Heap overflow in `QuantizeAndDequantizeV2`
CVE-2022-41910TensorFlowMedium4.8fixed in 2.8.4, 2.9.3, 2.10.1
Nov 212022Segfault in `CompositeTensorVariantToComponents`
CVE-2022-41909TensorFlowMedium4.8fixed in 2.8.4, 2.9.3, 2.10.1
Nov 212022`CHECK` fail via inputs in `PyFunc`
CVE-2022-41908TensorFlowMedium4.8fixed in 2.8.4, 2.9.3, 2.10.1
Nov 212022Overflow in `ResizeNearestNeighborGrad`
CVE-2022-41907TensorFlowMedium4.8fixed in 2.8.4, 2.9.3, 2.10.1
Nov 212022Out of bounds write in grappler in Tensorflow
CVE-2022-41902TensorFlowHigh7.1fixed in 2.8.4, 2.9.3, 2.10.1
Nov 212022`CHECK_EQ` fail via input in `SparseMatrixNNZ`
CVE-2022-41901TensorFlowMedium4.8fixed in 2.8.4, 2.9.3, 2.10.1
Nov 212022FractionalMaxPool and FractionalAVGPool heap out-of-bounds acess
CVE-2022-41900TensorFlowHigh7.1fixed in 2.8.4, 2.9.3, 2.10.1
Nov 212022`CHECK` fail via inputs in `SdcaOptimizer`
CVE-2022-41899TensorFlowMedium4.8fixed in 2.8.4, 2.9.3, 2.10.1
Nov 212022`CHECK` fail via inputs in `SparseFillEmptyRowsGrad`
CVE-2022-41898TensorFlowMedium4.8fixed in 2.8.4, 2.9.3, 2.10.1
Nov 212022`FractionalMaxPoolGrad` Heap out of bounds read
CVE-2022-41897TensorFlowMedium4.8fixed in 2.8.4, 2.9.3, 2.10.1
Nov 212022`tf.raw_ops.Mfcc` crashes
CVE-2022-41896TensorFlowMedium4.8fixed in 2.8.4, 2.9.3, 2.10.1
Nov 212022`MirrorPadGrad` heap out of bounds read
CVE-2022-41895TensorFlowMedium4.8fixed in 2.8.4, 2.9.3, 2.10.1
Nov 212022Buffer overflow in `CONV_3D_TRANSPOSE` on TFLite
CVE-2022-41894TensorFlowHigh7.1fixed in 2.8.4, 2.9.3, 2.10.1
Nov 212022`CHECK_EQ` fail in `tf.raw_ops.TensorListResize`
CVE-2022-41893TensorFlowMedium4.8fixed in 2.8.4, 2.9.3, 2.10.1

The newest 60. Each project page has the full list.

About Google

Google LLC is an American multinational technology corporation focused on information technology, online advertising, search engine technology, email, cloud computing, software, quantum computing, e-commerce, consumer electronics, and artificial intelligence (AI).

Elsewhere on fru.dev: Acquisitions · Paydays · Repos · TechConf · Trending

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.