📦 Keras

by Keras

🔍 What is Keras?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-1550

CRITICAL CVSS 9.8 Mar 11, 2025

CVE-2025-1550 is a critical remote code execution vulnerability in Keras where the Model.load_model function can execute arbitrary Python code even with safe_mode=True. Attackers can craft malicious ....

CVE-2024-3660

CRITICAL CVSS 9.8 Apr 16, 2024

This CVE describes a critical arbitrary code injection vulnerability in TensorFlow's Keras framework that allows attackers to execute arbitrary code with the same permissions as the vulnerable applica...

CVE-2026-1669

HIGH CVSS 7.5 Feb 11, 2026

This vulnerability allows remote attackers to read arbitrary local files on systems running vulnerable Keras versions by exploiting a flaw in the HDF5 model loading mechanism. Attackers can craft mali...

CVE-2026-0897

HIGH CVSS 7.5 Jan 15, 2026

This vulnerability allows remote attackers to cause Denial of Service (DoS) by sending a specially crafted .keras archive with an extremely large dataset shape declaration. When Keras attempts to load...

CVE-2025-9906

HIGH CVSS 7.3 Sep 19, 2025

CVE-2025-9906 is a critical vulnerability in Keras that allows arbitrary code execution when loading specially crafted .keras model files. Attackers can bypass safe_mode=True protection by embedding m...

CVE-2025-8747

HIGH CVSS 7.8 Aug 11, 2025

A safe mode bypass vulnerability in Keras allows attackers to execute arbitrary code by tricking users into loading malicious .keras model archives. This affects all users of Keras versions 3.0.0 thro...

CVE-2024-55459

MEDIUM CVSS 6.5 Jan 8, 2025

A vulnerability in Keras 3.7.0 allows attackers to write arbitrary files to a user's machine by exploiting the get_file function with a malicious tar archive. This affects any application using Keras ...