Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-49655

33
FAUCET Score

CVE-2025-49655 is a critical deserialization vulnerability affecting Keras framework versions 3.11.0 through 3.11.2, allowing arbitrary code execution when loading a malicious Keras file containing a TorchModuleWrapper class, even with safe mode enabled. This vulnerability carries a CVSS score of 9.8 (CRITICAL) due to its network-based attack vector, low attack complexity, and high impact on confidentiality, integrity, and availability. While no public exploits or active exploitation have been observed, and community discussion is minimal, the high FAUCET Risk Score indicates significant potential danger.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.11.0, < 3.11.3CPE match
cpe:2.3:a:keras:keras:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

9.8CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
0.70%
Probability of exploitation in next 30 days
EPSS Percentile
49.4%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0070 is in the 32nd percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (21)

pippatch availablevia ghsa
Product: kerasFixed in: 3.11.3
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-kserve-agent-rhel9:sha256:5a0d462e652464ae21e9152b6eac7d95c05d9d3d6884a3f1590c6194bda64ae7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-kserve-controller-rhel9:sha256:4bbfad1a5fde624a13c3edd27962e5b8bf7782ea4cd5f64b3a996d308e3be365
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-kserve-router-rhel9:sha256:bdb164d90a0ad4cf3640afb518371e7b91c7682cc0b1e98e025ca1d64b927efc
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-kserve-storage-initializer-rhel9:sha256:e9a1cdebc0511256b293f04741e81461d8113ef4cc891a9d85683aa862baaf7a
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-modelmesh-runtime-adapter-rhel9:sha256:bf9194f8e0885012b14da1cbe9a95e4b75bc80c8eada16b25e391ce035ba29d0
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-pipeline-runtime-datascience-cpu-py312-rhel9:sha256:b29f9abba7ed71b98ad10158dd68c5fe87acf28509438b56f38c2662d8616d75
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-pipeline-runtime-minimal-cpu-py312-rhel9:sha256:7ff9cd229efd9565a9f26d4f48a7000d54db330aeb38986f1438a8203a551185
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-pipeline-runtime-pytorch-cuda-py312-rhel9:sha256:f5373ddca575dc4bdb3ebd6910b0665f0a8c3c38454b4d0268c6a97e6f0ec81c
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-pipeline-runtime-pytorch-rocm-py312-rhel9:sha256:e621898c4dc4f07ad89d4eadd23c5732bc60cf6f42c8e3fd312463b232fc7740
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-pipeline-runtime-tensorflow-cuda-py312-rhel9:sha256:1931d2ff282436ab32f8cb4bee1cfa6d5484fd9d62273be4ec3ae5c1f7f9dcb2
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-workbench-codeserver-datascience-cpu-py312-rhel9:sha256:aaab63c67b960c96b07521844b358d04e8aef5ded5ac66f8ca33cd50d247bb3d
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-workbench-jupyter-datascience-cpu-py312-rhel9:sha256:1fbcee8de39474ba1b38561605cf19136f998d58b3739291c735d3cd843c0c79
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-workbench-jupyter-minimal-cpu-py312-rhel9:sha256:f79abc8a411d994d0af1ec388d10920ad61c34d4979a71998a8305f4feaf0fd4
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-workbench-jupyter-minimal-cuda-py312-rhel9:sha256:b72c710b2f2c27dea58d2edd2c515c78198630ffe9b5eae5aa25a26ebbef9460
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-workbench-jupyter-minimal-rocm-py312-rhel9:sha256:5d4a0a19aeb546b6a03efe003dd01826353968c91091773718f7603666efce46
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-workbench-jupyter-pytorch-cuda-py312-rhel9:sha256:af5beb652ee1f816bd0acac5b98866cb2ed45df4726bb8fe414f5f14f67cfe5e
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-workbench-jupyter-pytorch-rocm-py312-rhel9:sha256:346a4fdde7d4c3d3afba71760edf44730745eb8fde86ec6476a668cea607e7ba
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-workbench-jupyter-tensorflow-cuda-py312-rhel9:sha256:514e9edc09ab789ef1b409e1361d8be90dbfbd231eaad627e69f2301dd634934
View patch
redhatpatch availablevia redhat_api
Product: Red Hat OpenShift AI 2.25Fixed in: rhoai/odh-workbench-jupyter-trustyai-cpu-py312-rhel9:sha256:2d0c6bb9a4e81ea6a20b9ca4fde13108b56b3f91fa8e902c528c322288a38033
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Trusted Artifact Signer 1.3Fixed in: rhtas/model-transparency-rhel9:sha256:cdbf79af3951e2830df94331a890ab8f1e2649db72e96bec57fee61fc9add1e6
View patch

Vendor Advisories (2)

pipGHSA-cvhh-q5g5-qprpcritical

Keras framework vulnerable to deserialization of untrusted data

Oct 17, 2025
redhatCVE-2025-49655Important

keras: Keras deserialization of untrusted data

Oct 17, 2025

References

github.com / keras-team/keras/pull/21575
hiddenlayer.com / sai_security_advisor/2025-10-keras