{"data":{"ecosystem":"pypi","name":"keras","url":"https://aisecwatch.com/packages/pypi/keras","latestVersion":"3.15.1","firstReleaseAt":"2015-10-11T01:21:00.754Z","repository":"https://github.com/keras-team/keras","llm":{"exposure":"none","depth":null,"integratedAt":null,"integratedVersion":null,"sdks":[],"path":[]},"authority":{"profile":[],"fromDependencies":[]},"dependencies":[{"ecosystem":"pypi","name":"absl-py","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"h5py","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"ml-dtypes","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"namex","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"numpy","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"optree","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"packaging","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"rich","versionSpec":null,"scope":"runtime"}],"advisories":[{"id":"b0862dc1-8372-4b25-a9cf-a839596f2e52","url":"https://aisecwatch.com/issues/b0862dc1-8372-4b25-a9cf-a839596f2e52","cveId":"CVE-2026-12570","title":"CVE-2026-12570: A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading…","headline":"keras-team/keras denial of service via malicious .keras model files","severity":"medium","publishedAt":"2026-08-10T07:16:44.370Z","affected":["keras@< 3.15.0 (fixed: 3.15.0)"],"epssScore":0.00128,"matchedBy":"ecosystem"},{"id":"ecfb1588-08bf-4318-a066-f3d4ae36b664","url":"https://aisecwatch.com/issues/ecfb1588-08bf-4318-a066-f3d4ae36b664","cveId":"CVE-2026-9335","title":"CVE-2026-9335: A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to…","headline":"keras-team/keras local HDF5 file disclosure through ExternalLinks","severity":"high","publishedAt":"2026-08-02T05:16:20.827Z","affected":["keras@< 3.12.3 (fixed: 3.12.3)","keras@>= 3.13.0, < 3.15.0 (fixed: 3.15.0)"],"epssScore":0.00767,"matchedBy":"ecosystem"},{"id":"d756b1c3-28f8-4402-85ad-2f507a6541e4","url":"https://aisecwatch.com/issues/d756b1c3-28f8-4402-85ad-2f507a6541e4","cveId":"CVE-2026-12484","title":"CVE-2026-12484: A vulnerability in keras-team/keras version 3.15.0 allows unsafe deserialization of attacker-controlled PyTorch pickle…","headline":"keras-team/keras unsafe deserialization via TorchModuleWrapper.from_config","severity":"high","publishedAt":"2026-07-19T20:16:28.800Z","affected":["keras@< 3.12.3 (fixed: 3.12.3)","keras@>= 3.13.0, < 3.15.0 (fixed: 3.15.0)"],"epssScore":0.00393,"matchedBy":"ecosystem"},{"id":"9d229a57-7f45-4fd6-b584-7fa6ecb4b799","url":"https://aisecwatch.com/issues/9d229a57-7f45-4fd6-b584-7fa6ecb4b799","cveId":"CVE-2026-12482","title":"CVE-2026-12482: A vulnerability in keras-team/keras version 3.12.0 allows an attacker to craft a malicious tar archive that bypasses…","headline":"keras-team/keras tar extraction allows symlinks outside extraction directory","severity":"high","publishedAt":"2026-07-14T06:16:59.527Z","affected":["keras@< 3.12.3 (fixed: 3.12.3)","keras@>= 3.13.0, < 3.15.0 (fixed: 3.15.0)"],"epssScore":0.0033,"matchedBy":"ecosystem"},{"id":"4dae6fe8-e1ca-478a-83d9-da85f15f2b03","url":"https://aisecwatch.com/issues/4dae6fe8-e1ca-478a-83d9-da85f15f2b03","cveId":"CVE-2026-12481","title":"CVE-2026-12481: A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of…","headline":"keras-team/keras Lambda layer code execution through unsafe deserialization","severity":"critical","publishedAt":"2026-07-03T21:16:54.737Z","affected":["keras@< 3.12.3 (fixed: 3.12.3)","keras@>= 3.13.0, < 3.15.0 (fixed: 3.15.0)"],"epssScore":0.00719,"matchedBy":"ecosystem"},{"id":"66f5a4fc-e3e8-4f6c-85c9-77bfc74e6ce7","url":"https://aisecwatch.com/issues/66f5a4fc-e3e8-4f6c-85c9-77bfc74e6ce7","cveId":"CVE-2026-12480","title":"CVE-2026-12480: Keras versions up to and including 3.13.2 are vulnerable to an arbitrary HDF5 file read due to an incomplete fix for…","headline":"Keras arbitrary HDF5 file read through virtual datasets in model loading","severity":"medium","publishedAt":"2026-07-01T17:16:19.330Z","affected":["keras@< 3.12.3 (fixed: 3.12.3)","keras@>= 3.13.0, < 3.15.0 (fixed: 3.15.0)"],"epssScore":0.00175,"matchedBy":"ecosystem"},{"id":"0422f4a4-1e49-48aa-98a9-f81cf16102b9","url":"https://aisecwatch.com/issues/0422f4a4-1e49-48aa-98a9-f81cf16102b9","cveId":"CVE-2026-11816","title":"CVE-2026-11816: Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in…","headline":"Keras path traversal in archive extraction utilities","severity":"high","publishedAt":"2026-06-11T14:16:26.557Z","affected":["keras@< 3.14.0 (fixed: 3.14.0)"],"epssScore":0.00563,"matchedBy":"ecosystem"},{"id":"2f72e93a-6ea9-4681-aa18-201ddc7838f0","url":"https://aisecwatch.com/issues/2f72e93a-6ea9-4681-aa18-201ddc7838f0","cveId":"CVE-2026-0897","title":"GHSA-mgx6-5cf9-rr43: Keras vulnerable to DoS via Malicious .keras Model (HDF5 Shape Bomb Causes Petabyte Allocation in KerasFileEditor)","headline":null,"severity":"high","publishedAt":"2026-05-06T23:09:37.000Z","affected":["keras@>= 3.13.0, < 3.13.2 (fixed: 3.13.2)","keras@>= 3.0.0, <= 3.12.0 (fixed: 3.12.1)"],"epssScore":0.00335,"matchedBy":"ecosystem"},{"id":"7d2b9558-9839-4d43-b22e-27bc25073075","url":"https://aisecwatch.com/issues/7d2b9558-9839-4d43-b22e-27bc25073075","cveId":"CVE-2026-1462","title":"CVE-2026-1462: A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow…","headline":"Keras TFSMLayer loads attacker-controlled SavedModels despite safe_mode","severity":"high","publishedAt":"2026-04-13T15:17:18.967Z","affected":["keras@< 3.13.2 (fixed: 3.13.2)"],"epssScore":0.00405,"matchedBy":"ecosystem"},{"id":"c27c4d08-fa0b-4c56-8a7b-de342a4cced0","url":"https://aisecwatch.com/issues/c27c4d08-fa0b-4c56-8a7b-de342a4cced0","cveId":"CVE-2026-1669","title":"CVE-2026-1669: Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all…","headline":"Keras arbitrary file read in model loading via HDF5 integration","severity":"high","publishedAt":"2026-02-11T23:16:03.750Z","affected":["keras@>= 3.13.0, < 3.13.2 (fixed: 3.13.2)","keras@>= 3.0.0, < 3.12.1 (fixed: 3.12.1)"],"epssScore":0.00334,"matchedBy":"ecosystem"},{"id":"2a7e7b6e-f87a-47c1-8c1b-7e6dca20e339","url":"https://aisecwatch.com/issues/2a7e7b6e-f87a-47c1-8c1b-7e6dca20e339","cveId":"CVE-2025-12060","title":"CVE-2025-12060: The keras.utils.get_file API in Keras, when used with the extract=True option for tar archives, is vulnerable to a path…","headline":"Keras get_file path traversal via tar archive extraction","severity":"high","publishedAt":"2025-10-30T21:15:37.520Z","affected":["keras@<= 3.11.3 (fixed: 3.12.0)"],"epssScore":0.00631,"matchedBy":"ecosystem"},{"id":"0d6ec266-36c5-4f24-846d-86be6188810b","url":"https://aisecwatch.com/issues/0d6ec266-36c5-4f24-846d-86be6188810b","cveId":"CVE-2025-12058","title":"CVE-2025-12058: The Keras.Model.load_model method, including when executed with the intended security mitigation safe_mode=True, is…","headline":"Keras load_model arbitrary local file read and SSRF via StringLookup vocabulary","severity":"high","publishedAt":"2025-10-29T13:15:35.500Z","affected":["keras@< 3.12.0 (fixed: 3.12.0)"],"epssScore":0.00248,"matchedBy":"ecosystem"},{"id":"1327d022-e830-4f47-b3d1-471247239bd9","url":"https://aisecwatch.com/issues/1327d022-e830-4f47-b3d1-471247239bd9","cveId":"CVE-2025-49655","title":"CVE-2025-49655: Deserialization of untrusted data can occur in versions of the Keras framework running versions 3.11.0 up to but not…","headline":"Keras deserialization flaw allows code execution via malicious files","severity":"critical","publishedAt":"2025-10-17T20:15:37.420Z","affected":["keras@>= 3.11.0, < 3.11.3 (fixed: 3.11.3)"],"epssScore":0.0075,"matchedBy":"ecosystem"},{"id":"7f43d791-58d4-4732-8ed8-36ff248e5126","url":"https://aisecwatch.com/issues/7f43d791-58d4-4732-8ed8-36ff248e5126","cveId":"CVE-2025-9906","title":"CVE-2025-9906: The Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True. One…","headline":"Keras Model.load_model arbitrary code execution via crafted .keras archive","severity":"high","publishedAt":"2025-09-19T13:15:36.353Z","affected":["keras@< 3.11.0 (fixed: 3.11.0)"],"epssScore":0.00204,"matchedBy":"ecosystem"},{"id":"8f4ae7e5-d40b-4b45-8b16-30260414d108","url":"https://aisecwatch.com/issues/8f4ae7e5-d40b-4b45-8b16-30260414d108","cveId":"CVE-2025-9905","title":"CVE-2025-9905: The Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True. One…","headline":"Keras Model.load_model arbitrary code execution through crafted .h5 archives","severity":"high","publishedAt":"2025-09-19T13:15:36.033Z","affected":["keras@>= 3.0.0, < 3.11.3 (fixed: 3.11.3)"],"epssScore":0.00223,"matchedBy":"ecosystem"},{"id":"2d3ecbc5-66c0-425a-9870-3b859e913c88","url":"https://aisecwatch.com/issues/2d3ecbc5-66c0-425a-9870-3b859e913c88","cveId":"CVE-2025-8747","title":"CVE-2025-8747: A safe mode bypass vulnerability in the `Model.load_model` method in Keras versions 3.0.0 through 3.10.0 allows an…","headline":"Keras safe mode bypass in Model.load_model via crafted .keras archive","severity":"high","publishedAt":"2025-08-11T12:15:26.507Z","affected":["keras@>= 3.0.0, < 3.11.0 (fixed: 3.11.0)"],"epssScore":0.00118,"matchedBy":"ecosystem"},{"id":"6fd9b59f-f2e8-4895-8bbc-6c6201b848bf","url":"https://aisecwatch.com/issues/6fd9b59f-f2e8-4895-8bbc-6c6201b848bf","cveId":"CVE-2025-1550","title":"CVE-2025-1550: The Keras Model.load_model function permits arbitrary code execution, even with safe_mode=True, through a manually…","headline":"Keras Model.load_model arbitrary code execution via malicious .keras archive","severity":"critical","publishedAt":"2025-03-11T13:15:25.217Z","affected":["keras@>= 3.0.0, < 3.9.0 (fixed: 3.9.0)"],"epssScore":0.02626,"matchedBy":"ecosystem"},{"id":"0c8f31a9-9315-457b-9667-dde4b30030cc","url":"https://aisecwatch.com/issues/0c8f31a9-9315-457b-9667-dde4b30030cc","cveId":"CVE-2024-55459","title":"CVE-2024-55459: An issue in keras 3.7.0 allows attackers to write arbitrary files to the user's machine via downloading a crafted tar…","headline":"keras arbitrary file write through crafted tar file in get_file","severity":"medium","publishedAt":"2025-01-08T22:15:15.817Z","affected":["keras@<= 3.7.0"],"epssScore":0.00231,"matchedBy":"ecosystem"},{"id":"d9d50d58-c95e-4bf4-84d1-2951fc2e5277","url":"https://aisecwatch.com/issues/d9d50d58-c95e-4bf4-84d1-2951fc2e5277","cveId":"CVE-2024-3660","title":"CVE-2024-3660: A arbitrary code injection vulnerability in TensorFlow's Keras framework (<2.13) allows attackers to execute arbitrary…","headline":"TensorFlow Keras arbitrary code injection through crafted models","severity":"critical","publishedAt":"2024-04-17T01:15:08.603Z","affected":["keras@< 2.13.1rc0 (fixed: 2.13.1rc0)"],"epssScore":0.01745,"matchedBy":"ecosystem"}],"checkedAt":"2026-10-09T21:49:37.763Z"},"meta":{"advisoryMatching":"by package name and ecosystem; an advisory with no ecosystem recorded for the package is matched by name alone"}}