CVE-2026-0897 is a Denial of Service vulnerability affecting Google Keras versions 3.0.0 through 3.13.0 on all platforms. It stems from an "Allocation of Resources Without Limits or Throttling" flaw in the HDF5 weight loading component, allowing a remote attacker to trigger memory exhaustion and a Python interpreter crash. The vulnerability has a CVSS score of 7.5 (High), indicating a network-based attack with low complexity and high impact on availability. While there is no evidence of active exploitation, nor publicly available exploit code, the vulnerability has garnered significant community discussion, suggesting awareness among security researchers.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0.0, <= 3.13.0CPE matchmatch criteria | cpe:2.3:a:keras:keras:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Keras vulnerable to DoS via Malicious .keras Model (HDF5 Shape Bomb Causes Petabyte Allocation in KerasFileEditor)
May 6, 2026Duplicate Advisory: Google Keras Allocates Resources Without Limits or Throttling in the HDF5 weight loading component
Jan 15, 2026Keras: Keras: Denial of Service via crafted HDF5 weight loading file
Jan 15, 2026Denial of Service in Keras via Excessive Memory Allocation in HDF5 Metadata
Jan 13, 2026