Keras Vulnerabilities

pip ML Libraries

AI Threat Alert tracks 21 known vulnerabilities in Keras, 6 rated critical — an AI/ML ml libraries in the pip ecosystem. Each CVE includes CVSS severity, EPSS exploit probability, patch status, and CISO-grade analysis.

Data sources
60
Risk Score
21
Total CVEs
6
Critical
pip
Ecosystem
Aug 10, 2026
Last CVE
59%
Patch Rate
50d
Avg Time to Patch
64,232 stars 19,746 forks 216 issues 1,553 dependents Last push Aug 14, 2026
View on GitHub
OpenSSF Scorecard 7.1/10

Known Vulnerabilities (21 total, page 1 of 1)

Severity CVE ID Summary CVSS Published
UNKNOWN CVE-2026-12570 Keras: OOM DoS via malicious .keras model load -- Aug 10, 2026 MEDIUM CVE-2026-9335 A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalLinks. The `KerasFileEditor` and `keras.saving.load_weights` functions bypass the `safe_get_h5_group` and `safe_get_h5_dataset` helpers, which are designed to reject ExternalLinks and SoftLinks. This results in automatic dereferencing of links to external HDF5 files, enabling attackers to disclose sensitive data from the victim's local filesystem. Sp 6.5 Aug 2, 2026 HIGH CVE-2026-12484 Keras: unsafe pickle deserialization allows RCE 7.8 Jul 19, 2026 LOW CVE-2026-12482 Keras: symlink bypass enables tar path traversal 3.1 Jul 14, 2026 CRITICAL CVE-2026-12481 Keras: safe_mode=None bypass enables Lambda RCE 9.8 Jul 3, 2026 MEDIUM CVE-2026-12480 Keras: incomplete fix reopens HDF5 arbitrary file read 5.5 Jul 1, 2026 MEDIUM CVE-2026-12479 Keras: path traversal via layer names allows arbitrary file write 6.1 Jun 22, 2026 HIGH CVE-2026-11816 Keras: path traversal allows arbitrary file write 8.1 Jun 11, 2026 HIGH CVE-2026-1462 Keras: safe_mode bypass allows RCE via model deserialization 8.8 Apr 13, 2026 HIGH CVE-2026-0897 keras: Resource Exhaustion enables DoS 7.6 Jan 15, 2026 HIGH CVE-2026-1669 keras: File Control enables path manipulation 7.5 Feb 11, 2026 CRITICAL CVE-2025-12060 keras: Path Traversal enables file access 9.8 Oct 30, 2025 MEDIUM CVE-2025-12058 Keras: safe_mode bypass enables file read and SSRF -- Oct 29, 2025 CRITICAL CVE-2025-49655 keras: Deserialization enables RCE 9.8 Oct 17, 2025 HIGH CVE-2025-9906 Keras: safe_mode bypass enables RCE via model load 7.3 Sep 19, 2025 HIGH CVE-2025-9905 Keras: safe_mode bypass enables RCE via .h5 model files 7.3 Sep 19, 2025 HIGH CVE-2025-8747 Keras: safe mode bypass enables RCE via model load 7.8 Aug 11, 2025 CRITICAL CVE-2025-1550 Keras: safe_mode bypass enables RCE via model loading 9.8 Mar 11, 2025 MEDIUM CVE-2024-55459 Keras: path traversal enables arbitrary file write 6.5 Jan 8, 2025 CRITICAL CVE-2024-49326 Affiliator WP Plugin: Unauthenticated Web Shell Upload 9.8 Oct 20, 2024 CRITICAL CVE-2024-3660 Keras: RCE via malicious model deserialization 9.8 Apr 16, 2024

Frequently asked questions

What is Keras?

Keras is an AI/ML ml libraries tracked by AI Threat Alert for security vulnerabilities in the pip ecosystem.

How many known vulnerabilities does Keras have?

Keras has 21 known CVEs, 6 of them critical, tracked from NVD and GitHub Advisory.

Which ecosystem is Keras distributed in?

Keras is distributed via the pip ecosystem and categorized as ml libraries.

Where does the Keras vulnerability data come from?

Vulnerability data is sourced from NVD and GitHub Advisory, enriched with CVSS, EPSS, exploit signals, and patch status for each CVE.

How do I assess the risk of Keras?

Review each CVE below — every entry shows CVSS severity, EPSS exploit probability, exploitation signals, and whether a patched version is available.

Monitor Keras in your stack

Get instant alerts when new vulnerabilities affect Keras. CISO analysis, ATLAS technique mappings, and compliance reports included.

Start Monitoring