Skip to content

Keras security advisories

20 advisories · 8 critical or high in 12 months · latest Aug 10

20 advisories

DateAdvisory
Aug 10Keras model loading is vulnerable to denial of service through HDF5 shape bombs
CVE-2026-12570Medium5.5fixed in 3.15.0
Aug 2Keras: HDF5 links can disclose local file contents
CVE-2026-9335Medium6.5fixed in 3.12.3, 3.15.0
Jul 19Keras: TorchModuleWrapper can deserialize unsafe PyTorch pickle data
CVE-2026-12484High7.8fixed in 3.12.3, 3.15.0
Jul 14Keras: tar extraction permits symlink-based path traversal
CVE-2026-12482Low3.1fixed in 3.12.3, 3.15.0
Jul 3Keras: Lambda deserialization can bypass safe mode and execute code
CVE-2026-12481High8.8fixed in 3.12.3, 3.15.0
Jul 1Keras: HDF5 virtual datasets can disclose local files
CVE-2026-12480Medium5.5fixed in 3.12.3, 3.15.0
Jun 22Keras: DiskIOStore permits path traversal through crafted layer names
CVE-2026-12479Medium6.1fixed in 3.12.3, 3.15.0
Jun 11Keras archive extraction utilities allow path traversal and arbitrary file writes
CVE-2026-11816High8.1fixed in 3.14.0
May 6Keras vulnerable to DoS via Malicious .keras Model (HDF5 Shape Bomb Causes Petabyte Allocation in KerasFileEditor)
CVE-2026-0897Highfixed in 3.12.1, 3.13.2
Apr 13Keras has an untrusted deserialization vulnerability
CVE-2026-1462High8.8fixed in 3.13.2
Feb 18Keras has a Local File Disclosure via HDF5 External Storage During Keras Weight Loading
CVE-2026-1669High7.1fixed in 3.12.1, 3.13.2
Dec 22025Keras Directory Traversal Vulnerability
CVE-2025-12060High9.8fixed in 3.12.0
Oct 292025Keras is vulnerable to arbitrary local file loading and Server-Side Request Forgery
CVE-2025-12058Mediumfixed in 3.12.0
Oct 172025Keras framework vulnerable to deserialization of untrusted data
CVE-2025-49655Critical9.8fixed in 3.11.3
Sep 192025The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded.
CVE-2025-9905Highfixed in 3.11.3
Sep 192025Keras is vulnerable to Deserialization of Untrusted Data
CVE-2025-9906High7.3fixed in 3.11.0
Aug 122025Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality
CVE-2025-8747High8.8fixed in 3.11.0
Mar 112025Arbitrary Code Execution via Crafted Keras Config for Model Loading
CVE-2025-1550Highfixed in 3.9.0
Jan 82025keras Path Traversal vulnerability
CVE-2024-55459Mediumno fix yet
Apr 162024Keras code injection vulnerability
CVE-2024-3660Critical9.8fixed in 2.13.1rc0
About Keras

The multi-backend deep learning API.

Packages watched: keras (PyPI).

Google elsewhere on fru.dev: Acquisitions · Paydays · Repos · TechConf · Trending

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.