Google Vulnerabilities and Affected Products
Vulnerabilities associated with Keras.
Products
Clear product- Chrome4,306 vulnerabilities
- Android1,376 vulnerabilities
- pixel56 vulnerabilities
- Chromium V839 vulnerabilities
- ChromeOS12 vulnerabilities
- android_kernel6 vulnerabilities
- AngularJS6 vulnerabilities
- Chromium6 vulnerabilities
- gRPC6 vulnerabilities
- MCP Toolbox for Databases (googleapis/mcp-toolbox)6 vulnerabilities
- mcp-toolbox5 vulnerabilities
- gVisor4 vulnerabilities
- Keras4 vulnerabilities
- Nearby3 vulnerabilities
- admob2 vulnerabilities
- Andrioid2 vulnerabilities
- Chromium Blink2 vulnerabilities
- Chromium Intents2 vulnerabilities
- Chromium Mojo2 vulnerabilities
- Chromium Skia2 vulnerabilities
- Fuchsia2 vulnerabilities
- libjxl2 vulnerabilities
- MCP Toolbox for Databases2 vulnerabilities
- Nest Wifi Pro2 vulnerabilities
- Omaha2 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2026-1669HIGH | Arbitrary File Read in Keras via HDF5 External DatasetsArbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose sensitive information via a crafted .keras model file utilizing HDF5 external dataset references. | CVSS7.1v4.0 | EPSS0.298% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2026-0897HIGH | Denial of Service in Keras via Excessive Memory Allocation in HDF5 MetadataAllocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and a crash of the Python interpreter via a crafted .keras archive containing a valid model.weights.h5 file whose dataset declares an extremely large shape. CWE-770Jan 15, 2026 | CVSS7.1v4.0 | EPSS0.299% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-8747HIGH | Keras safe_mode bypass allows arbitrary code execution when loading a malicious model.A safe mode bypass vulnerability in the `Model.load_model` method in Keras versions 3.0.0 through 3.10.0 allows an attacker to achieve arbitrary code execution by convincing a user to load a specially crafted `.keras` model archive. CWE-502Aug 11, 2025 | CVSS8.6v4.0 | EPSS0.116% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2025-1550HIGH | Arbitrary Code Execution via Crafted Keras Config for Model LoadingThe Keras Model.load_model function permits arbitrary code execution, even with safe_mode=True, through a manually constructed, malicious .keras archive. By altering the config.json file within the archive, an attacker can specify arbitrary Python modules and functions, along with their arguments, to be loaded and executed during model loading. | CVSS7.3v4.0 | EPSS2.58% | PoCs2 | SignalsNot listed in CISA KEVNo known ransomware use1 Nuclei template | STIX |