{"schema_version":1,"title":"Keras (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 21 vulnerabilities in Keras (PyPI): 0 in the last 7 days and 8 in the last 90 days, 0 of them critical and 0 exploited in the wild. The most recent, CVE-2026-12570, was published on 10 August 2026.","url":"https://junglewise.ai/threats/technologies/keras","json_url":"https://junglewise.ai/threats/technologies/keras.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/keras","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":10,"all_time":21,"critical":0,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":8,"last_365_days":16},"latest":[{"cve":"CVE-2026-12570","cvss":5.5,"epss":0.0013,"slug":"cve-2026-12570-keras-model-loading-denial-of-service-via-hdf5-shape-bombs","title":"Keras model loading denial of service via HDF5 shape bombs","severity":"medium","exploited":false,"published_at":"2026-08-10T09:31:20+00:00","url":"https://junglewise.ai/threats/cve-2026-12570-keras-model-loading-denial-of-service-via-hdf5-shape-bombs"},{"cve":"CVE-2026-9335","cvss":6.5,"epss":0.0077,"slug":"cve-2026-9335-keras-hdf5-arbitrary-file-disclosure-via-externallinks","title":"A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5","severity":"medium","exploited":false,"published_at":"2026-08-02T05:16:20.827+00:00","url":"https://junglewise.ai/threats/cve-2026-9335-keras-hdf5-arbitrary-file-disclosure-via-externallinks"},{"cve":"CVE-2026-12484","cvss":7.8,"epss":0.0039,"slug":"cve-2026-12484-keras-unsafe-deserialization-in-torchmodulewrapper","title":"Keras unsafe deserialization in TorchModuleWrapper","severity":"high","exploited":false,"published_at":"2026-07-19T20:16:28.8+00:00","url":"https://junglewise.ai/threats/cve-2026-12484-keras-unsafe-deserialization-in-torchmodulewrapper"},{"cve":"CVE-2026-12482","cvss":3.1,"epss":0.0033,"slug":"cve-2026-12482-keras-path-traversal-via-symlink-in-filter-safe-tarinfos","title":"Keras path traversal via symlink in filter_safe_tarinfos","severity":"low","exploited":false,"published_at":"2026-07-14T06:16:59.527+00:00","url":"https://junglewise.ai/threats/cve-2026-12482-keras-path-traversal-via-symlink-in-filter-safe-tarinfos"},{"cve":"CVE-2025-12060","cvss":3.1,"epss":0.0059,"slug":"cve-2025-12060-keras-directory-traversal-vulnerability","title":"PYSEC-2026-1486 - Keras Directory Traversal Vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:11.745777+00:00","url":"https://junglewise.ai/threats/cve-2025-12060-keras-directory-traversal-vulnerability"},{"cve":"CVE-2025-12058","cvss":4,"epss":0.0025,"slug":"cve-2025-12058-keras-is-vulnerable-to-arbitrary-local-file-loading-and-server","title":"PYSEC-2026-1487 - Keras is vulnerable to arbitrary local file loading and Server-Side Request Forgery","severity":"medium","exploited":false,"published_at":"2026-07-07T16:03:08.498075+00:00","url":"https://junglewise.ai/threats/cve-2025-12058-keras-is-vulnerable-to-arbitrary-local-file-loading-and-server"},{"cve":"CVE-2026-12481","cvss":8.8,"epss":0.0072,"slug":"cve-2026-12481-keras-team-keras-arbitrary-code-execution-in-lambda-layer","title":"Keras Team Keras arbitrary code execution in Lambda layer","severity":"high","exploited":false,"published_at":"2026-07-03T21:16:54.737+00:00","url":"https://junglewise.ai/threats/cve-2026-12481-keras-team-keras-arbitrary-code-execution-in-lambda-layer"},{"cve":"CVE-2026-12480","cvss":5.5,"epss":0.0018,"slug":"cve-2026-12480-keras-arbitrary-hdf5-file-read-in-model-loading","title":"Keras arbitrary HDF5 file read in model loading","severity":"medium","exploited":false,"published_at":"2026-07-01T17:16:19.33+00:00","url":"https://junglewise.ai/threats/cve-2026-12480-keras-arbitrary-hdf5-file-read-in-model-loading"},{"cve":"CVE-2024-3660","cvss":3.1,"epss":0.0175,"slug":"cve-2024-3660-keras-code-injection-vulnerability","title":"PYSEC-2026-369 - Keras code injection vulnerability","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:39.628931+00:00","url":"https://junglewise.ai/threats/cve-2024-3660-keras-code-injection-vulnerability"},{"cve":"CVE-2025-49655","cvss":3.1,"epss":0.0075,"slug":"cve-2025-49655-keras-framework-vulnerable-to-deserialization-of-untrusted-data","title":"PYSEC-2026-368 - Keras framework vulnerable to deserialization of untrusted data","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:37.095983+00:00","url":"https://junglewise.ai/threats/cve-2025-49655-keras-framework-vulnerable-to-deserialization-of-untrusted-data"},{"cve":"CVE-2026-12479","cvss":6.1,"epss":0.0038,"slug":"cve-2026-12479-keras-team-keras-path-traversal-in-diskiostore-make","title":"Keras Team Keras path traversal in DiskIOStore.make","severity":"medium","exploited":false,"published_at":"2026-06-22T16:16:33.953+00:00","url":"https://junglewise.ai/threats/cve-2026-12479-keras-team-keras-path-traversal-in-diskiostore-make"},{"cve":"CVE-2026-11816","cvss":8.1,"epss":0.0056,"slug":"cve-2026-11816-keras-path-traversal-in-archive-extraction-utilities","title":"Keras path traversal in archive extraction utilities","severity":"high","exploited":false,"published_at":"2026-06-11T14:16:26.557+00:00","url":"https://junglewise.ai/threats/cve-2026-11816-keras-path-traversal-in-archive-extraction-utilities"},{"cve":"CVE-2026-1462","cvss":8.8,"epss":0.0041,"slug":"cve-2026-1462-keras-tfsmlayer-arbitrary-code-execution-via-safe-mode-bypass","title":"Keras TFSMLayer arbitrary code execution via safe_mode bypass","severity":"high","exploited":false,"published_at":"2026-04-13T15:17:18.967+00:00","url":"https://junglewise.ai/threats/cve-2026-1462-keras-tfsmlayer-arbitrary-code-execution-via-safe-mode-bypass"},{"cve":"CVE-2026-1669","cvss":7.5,"epss":0.0031,"slug":"cve-2026-1669-google-keras-arbitrary-file-read-in-hdf5-model-loading","title":"Google Keras arbitrary file read in HDF5 model loading","severity":"high","exploited":false,"published_at":"2026-02-11T23:16:03.75+00:00","url":"https://junglewise.ai/threats/cve-2026-1669-google-keras-arbitrary-file-read-in-hdf5-model-loading"},{"cve":"CVE-2026-0897","cvss":7.5,"epss":0.0034,"slug":"cve-2026-0897-google-keras-denial-of-service-via-hdf5-shape-bomb-in-weight","title":"Google Keras Denial of Service via HDF5 shape bomb in weight loading","severity":"high","exploited":false,"published_at":"2026-01-15T14:16:26.89+00:00","url":"https://junglewise.ai/threats/cve-2026-0897-google-keras-denial-of-service-via-hdf5-shape-bomb-in-weight"},{"cvss":4,"slug":"keras-keras-utils-get-file-path-traversal-in-tar-extraction-d88c39fb","title":"Keras keras.utils.get_file path traversal in TAR extraction","severity":"medium","exploited":false,"published_at":"2025-10-30T18:31:10+00:00","url":"https://junglewise.ai/threats/keras-keras-utils-get-file-path-traversal-in-tar-extraction-d88c39fb"},{"cve":"CVE-2025-9905","cvss":4,"epss":0.0022,"slug":"cve-2025-9905-keras-arbitrary-code-execution-via-safe-mode-bypass-in-h5-loading","title":"Keras arbitrary code execution via safe_mode bypass in H5 loading","severity":"high","exploited":false,"published_at":"2025-09-19T20:12:05+00:00","url":"https://junglewise.ai/threats/cve-2025-9905-keras-arbitrary-code-execution-via-safe-mode-bypass-in-h5-loading"},{"cve":"CVE-2025-9906","cvss":7.3,"epss":0.002,"slug":"cve-2025-9906-keras-arbitrary-code-execution-via-untrusted-model-deserialization","title":"Keras arbitrary code execution via untrusted model deserialization","severity":"high","exploited":false,"published_at":"2025-09-19T09:31:14+00:00","url":"https://junglewise.ai/threats/cve-2025-9906-keras-arbitrary-code-execution-via-untrusted-model-deserialization"},{"cve":"CVE-2025-8747","cvss":8.8,"epss":0.0012,"slug":"cve-2025-8747-keras-safe-mode-bypass-via-internal-function-reuse","title":"Keras safe_mode bypass via internal function reuse","severity":"high","exploited":false,"published_at":"2025-08-12T19:33:07+00:00","url":"https://junglewise.ai/threats/cve-2025-8747-keras-safe-mode-bypass-via-internal-function-reuse"},{"cve":"CVE-2025-1550","cvss":4,"epss":0.0263,"slug":"cve-2025-1550-keras-arbitrary-code-execution-in-model-load-model","title":"Keras arbitrary code execution in Model.load_model","severity":"high","exploited":false,"published_at":"2025-03-11T20:07:32+00:00","url":"https://junglewise.ai/threats/cve-2025-1550-keras-arbitrary-code-execution-in-model-load-model"},{"cve":"CVE-2024-55459","cvss":4,"epss":0.0023,"slug":"cve-2024-55459-keras-path-traversal-in-get-file-function","title":"Keras path traversal in get_file function","severity":"medium","exploited":false,"published_at":"2025-01-08T18:30:48+00:00","url":"https://junglewise.ai/threats/cve-2024-55459-keras-path-traversal-in-get-file-function"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":2},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"Keras (PyPI)","slug":"keras","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"category":"library","homepage":"https://keras.io/","repo_url":"https://github.com/keras-team/keras","description":"A high-level deep learning API developed by the Keras Team, designed for human beings and built on top of JAX, TensorFlow, and PyTorch.","url":"https://junglewise.ai/threats/technologies/keras"},"most_severe":[{"cve":"CVE-2026-12481","cvss":8.8,"epss":0.0072,"slug":"cve-2026-12481-keras-team-keras-arbitrary-code-execution-in-lambda-layer","title":"Keras Team Keras arbitrary code execution in Lambda layer","severity":"high","exploited":false,"published_at":"2026-07-03T21:16:54.737+00:00","url":"https://junglewise.ai/threats/cve-2026-12481-keras-team-keras-arbitrary-code-execution-in-lambda-layer"},{"cve":"CVE-2026-1462","cvss":8.8,"epss":0.0041,"slug":"cve-2026-1462-keras-tfsmlayer-arbitrary-code-execution-via-safe-mode-bypass","title":"Keras TFSMLayer arbitrary code execution via safe_mode bypass","severity":"high","exploited":false,"published_at":"2026-04-13T15:17:18.967+00:00","url":"https://junglewise.ai/threats/cve-2026-1462-keras-tfsmlayer-arbitrary-code-execution-via-safe-mode-bypass"},{"cve":"CVE-2025-8747","cvss":8.8,"epss":0.0012,"slug":"cve-2025-8747-keras-safe-mode-bypass-via-internal-function-reuse","title":"Keras safe_mode bypass via internal function reuse","severity":"high","exploited":false,"published_at":"2025-08-12T19:33:07+00:00","url":"https://junglewise.ai/threats/cve-2025-8747-keras-safe-mode-bypass-via-internal-function-reuse"},{"cve":"CVE-2026-11816","cvss":8.1,"epss":0.0056,"slug":"cve-2026-11816-keras-path-traversal-in-archive-extraction-utilities","title":"Keras path traversal in archive extraction utilities","severity":"high","exploited":false,"published_at":"2026-06-11T14:16:26.557+00:00","url":"https://junglewise.ai/threats/cve-2026-11816-keras-path-traversal-in-archive-extraction-utilities"},{"cve":"CVE-2026-12484","cvss":7.8,"epss":0.0039,"slug":"cve-2026-12484-keras-unsafe-deserialization-in-torchmodulewrapper","title":"Keras unsafe deserialization in TorchModuleWrapper","severity":"high","exploited":false,"published_at":"2026-07-19T20:16:28.8+00:00","url":"https://junglewise.ai/threats/cve-2026-12484-keras-unsafe-deserialization-in-torchmodulewrapper"},{"cve":"CVE-2026-0897","cvss":7.5,"epss":0.0034,"slug":"cve-2026-0897-google-keras-denial-of-service-via-hdf5-shape-bomb-in-weight","title":"Google Keras Denial of Service via HDF5 shape bomb in weight loading","severity":"high","exploited":false,"published_at":"2026-01-15T14:16:26.89+00:00","url":"https://junglewise.ai/threats/cve-2026-0897-google-keras-denial-of-service-via-hdf5-shape-bomb-in-weight"},{"cve":"CVE-2026-1669","cvss":7.5,"epss":0.0031,"slug":"cve-2026-1669-google-keras-arbitrary-file-read-in-hdf5-model-loading","title":"Google Keras arbitrary file read in HDF5 model loading","severity":"high","exploited":false,"published_at":"2026-02-11T23:16:03.75+00:00","url":"https://junglewise.ai/threats/cve-2026-1669-google-keras-arbitrary-file-read-in-hdf5-model-loading"},{"cve":"CVE-2025-9906","cvss":7.3,"epss":0.002,"slug":"cve-2025-9906-keras-arbitrary-code-execution-via-untrusted-model-deserialization","title":"Keras arbitrary code execution via untrusted model deserialization","severity":"high","exploited":false,"published_at":"2025-09-19T09:31:14+00:00","url":"https://junglewise.ai/threats/cve-2025-9906-keras-arbitrary-code-execution-via-untrusted-model-deserialization"},{"cve":"CVE-2025-1550","cvss":4,"epss":0.0263,"slug":"cve-2025-1550-keras-arbitrary-code-execution-in-model-load-model","title":"Keras arbitrary code execution in Model.load_model","severity":"high","exploited":false,"published_at":"2025-03-11T20:07:32+00:00","url":"https://junglewise.ai/threats/cve-2025-1550-keras-arbitrary-code-execution-in-model-load-model"},{"cve":"CVE-2025-9905","cvss":4,"epss":0.0022,"slug":"cve-2025-9905-keras-arbitrary-code-execution-via-safe-mode-bypass-in-h5-loading","title":"Keras arbitrary code execution via safe_mode bypass in H5 loading","severity":"high","exploited":false,"published_at":"2025-09-19T20:12:05+00:00","url":"https://junglewise.ai/threats/cve-2025-9905-keras-arbitrary-code-execution-via-safe-mode-bypass-in-h5-loading"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}