Keras versions up to 3.14.0 fail to enforce their own HDF5 safety checks, letting a malicious .h5, .weights.h5, or .keras file use HDF5 ExternalLinks to pull arbitrary local file content into memory the moment it's loaded via KerasFileEditor or keras.saving.load_weights. This matters because Keras sits under 1,553 downstream packages and is a routine part of model-sharing workflows — any data scientist opening a 'pretrained checkpoint' from a colleague, forum, or model hub is a viable victim, and the CVSS confidentiality-only score (6.5) undersells the risk in environments where model files carry credentials or config alongside weights. Exploitation requires no special privileges beyond convincing someone to load the file (UI:R), which keeps the EPSS score low (0.65%, top 52th percentile) and it's not in CISA KEV or paired with a public exploit or Nuclei template — CISA rates it TRACK, not urgent action. Patch to keras >= 3.12.3 (fixed in 3.15.0) immediately across ML training and inference environments, and until then treat any .h5/.keras/.weights.h5 file from outside your organization as untrusted input requiring sandboxed inspection before loading.
What is the risk?
Medium severity, confidentiality-only impact (CVSS 6.5, C:H/I:N/A:N). Exploitability is moderate: the attacker needs zero authentication and low complexity, but user interaction is required (a victim must actively load the malicious model/weights file), which caps real-world exploitation velocity. No KEV listing, no public PoC, and no Nuclei template exist, and CISA SSVC rates it TRACK rather than Act/Attend — this is not an actively exploited or trivially wormable bug. The real risk driver is exposure surface: Keras' massive install base (1,553 dependents) and the routine practice of sharing/loading model checkpoints from external sources (Hugging Face, forums, collaborators) creates many plausible delivery paths even without a public exploit.
How does the attack unfold?
What systems are affected?
| Package | Ecosystem | Vulnerable Range | Patched |
|---|---|---|---|
| Keras | pip | < 3.12.3 | 3.12.3 |
Do you use Keras? You're affected.
How severe is it?
What is the attack surface?
What should I do?
1 step-
1) Upgrade to keras >= 3.12.3 (or 3.15.0) immediately across all environments that load .h5/.weights.h5/.keras files — this is the only complete fix, since the vulnerable code path bypasses the library's own link-rejection helpers. 2) Until patched, treat model files from untrusted or unverified sources (model hubs, email, forums, external collaborators) as hostile input: load them only in an isolated/sandboxed environment with no sensitive files reachable, and never load them as the same user with access to credentials or secrets. 3) Detection: audit incoming .h5/.keras files for embedded HDF5 ExternalLink/SoftLink references (h5dump or h5py can enumerate links) before they reach production loading code. 4) Pin and monitor keras version in dependency manifests (requirements.txt, pyproject.toml) and flag any pre-3.12.3 installs in SBOM/dependency scanning.
What does CISA's SSVC say?
Source: CISA Vulnrichment (SSVC v2.0). Decision based on the CISA Coordinator decision tree.
How is it classified?
Which compliance frameworks are affected?
This CVE is relevant to:
Frequently Asked Questions
What is CVE-2026-9335?
Keras versions up to 3.14.0 fail to enforce their own HDF5 safety checks, letting a malicious .h5, .weights.h5, or .keras file use HDF5 ExternalLinks to pull arbitrary local file content into memory the moment it's loaded via KerasFileEditor or keras.saving.load_weights. This matters because Keras sits under 1,553 downstream packages and is a routine part of model-sharing workflows — any data scientist opening a 'pretrained checkpoint' from a colleague, forum, or model hub is a viable victim, and the CVSS confidentiality-only score (6.5) undersells the risk in environments where model files carry credentials or config alongside weights. Exploitation requires no special privileges beyond convincing someone to load the file (UI:R), which keeps the EPSS score low (0.65%, top 52th percentile) and it's not in CISA KEV or paired with a public exploit or Nuclei template — CISA rates it TRACK, not urgent action. Patch to keras >= 3.12.3 (fixed in 3.15.0) immediately across ML training and inference environments, and until then treat any .h5/.keras/.weights.h5 file from outside your organization as untrusted input requiring sandboxed inspection before loading.
Is CVE-2026-9335 actively exploited?
No confirmed active exploitation of CVE-2026-9335 has been reported, but organizations should still patch proactively.
How to fix CVE-2026-9335?
1) Upgrade to keras >= 3.12.3 (or 3.15.0) immediately across all environments that load .h5/.weights.h5/.keras files — this is the only complete fix, since the vulnerable code path bypasses the library's own link-rejection helpers. 2) Until patched, treat model files from untrusted or unverified sources (model hubs, email, forums, external collaborators) as hostile input: load them only in an isolated/sandboxed environment with no sensitive files reachable, and never load them as the same user with access to credentials or secrets. 3) Detection: audit incoming .h5/.keras files for embedded HDF5 ExternalLink/SoftLink references (h5dump or h5py can enumerate links) before they reach production loading code. 4) Pin and monitor keras version in dependency manifests (requirements.txt, pyproject.toml) and flag any pre-3.12.3 installs in SBOM/dependency scanning.
What systems are affected by CVE-2026-9335?
This vulnerability affects the following AI/ML architecture patterns: training pipelines, model serving, MLOps model registries, model sharing/distribution workflows.
What is the CVSS score for CVE-2026-9335?
CVE-2026-9335 has a CVSS v3.1 base score of 6.5 (MEDIUM). The EPSS exploitation probability is 0.77%.
What is the AI security impact?
Affected AI Architectures
MITRE ATLAS Techniques
AML.T0011.000 Unsafe AI Artifacts AML.T0025 Exfiltration via Cyber Means AML.T0037 Data from Local System Compliance Controls Affected
What are the technical details?
Original Advisory
A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalLinks. The `KerasFileEditor` and `keras.saving.load_weights` functions bypass the `safe_get_h5_group` and `safe_get_h5_dataset` helpers, which are designed to reject ExternalLinks and SoftLinks. This results in automatic dereferencing of links to external HDF5 files, enabling attackers to disclose sensitive data from the victim's local filesystem. Specifically, `KerasFileEditor` extracts attributes and datasets from linked files into its internal structures, while `keras.saving.load_weights` loads weights from linked files into the user's model. This issue can be exploited by providing a malicious `.h5`, `.weights.h5`, or `.keras` file containing ExternalLinks.
Exploitation Scenario
An attacker publishes a Keras model checkpoint (e.g., a 'fine-tuned' .keras file) on a model-sharing forum, GitHub repo, or via a phishing email targeting an ML engineer, embedding an HDF5 ExternalLink that points to a sensitive local path such as ~/.aws/credentials, ~/.ssh/id_rsa, or an internal config file. When the victim loads the file with keras.saving.load_weights to reuse the 'pretrained' weights, or opens it in KerasFileEditor to inspect/edit it, Keras automatically dereferences the ExternalLink and pulls the external file's contents into the model's internal attributes/dataset structures or the editor's in-memory state — bypassing the safe_get_h5_group/safe_get_h5_dataset checks meant to block exactly this. The disclosed data now lives inside the loaded model object, where it can be exfiltrated if the victim later serializes, shares, or uploads that model, or directly inspected by the attacker if they have any subsequent access to the victim's session or environment.
Weaknesses (CWE)
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Primary
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Primary
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') CWE-22 — Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'): The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
- [Implementation] Assume all input is malicious. Use an "accept known good" input validation strategy, i.e., use a list of acceptable inputs that strictly conform to specifications. Reject any input that does not strictly conform to specifications, or transform it into something that does. When performing input validation, consider all potentially relevant properties, including length, type of input, the full range of acceptable values, missing or extra inputs, syntax, consistency across related fields, and conformance to business rules. As an example of business rule logic, "boat" may be syntactically valid because it only contains alphanumeric characters, but it is not valid if the input is only expected to contain colors such as "red" or "blue." Do not rely exclusively on looking for malicious or malformed inputs. This is likely to miss at least one undesirable input, especially if the code's environment changes. This can give attackers enough room to bypass the intended validation. However, denylis
- [Architecture and Design] For any security checks that are performed on the client side, ensure that these checks are duplicated on the server side, in order to avoid CWE-602. Attackers can bypass the client-side checks by modifying values after the checks have been performed, or by changing the client to remove the client-side checks entirely. Then, these modified values would be submitted to the server.
Source: MITRE CWE corpus.
CVSS Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N References
- github.com/advisories/GHSA-m8wh-29wm-52mv
- github.com/keras-team/keras/commit/d338a45204bdc787c8b3c4a9b82c1911cd52dedf
- github.com/keras-team/keras/pull/22899
- github.com/keras-team/keras/pull/23165
- github.com/keras-team/keras/releases/tag/v3.12.3
- github.com/keras-team/keras/releases/tag/v3.15.0
- nvd.nist.gov/vuln/detail/CVE-2026-9335
- github.com/keras-team/keras/commit/23370f16b0ab9a200f7550a34e54a3ceab74ba0e
- huntr.com/bounties/876a7226-5428-4a66-9d05-232461120db5
Timeline
Related Vulnerabilities
CVE-2025-49655 9.8 keras: Deserialization enables RCE
Same package: keras CVE-2025-1550 9.8 Keras: safe_mode bypass enables RCE via model loading
Same package: keras CVE-2024-3660 9.8 Keras: RCE via malicious model deserialization
Same package: keras CVE-2024-49326 9.8 Affiliator WP Plugin: Unauthenticated Web Shell Upload
Same package: keras CVE-2025-12060 9.8 keras: Path Traversal enables file access
Same package: keras