Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Keras

First CVE: Apr 16, 2024Active for: 2 yearsTotal CVEs: 14
61.0
VTI Score
TOP TARGET

Keras is a widely used deep-learning library that sits as a critical dependency across machine-learning and data-science workflows, despite maintaining a very focused product footprint. Vulnerabilities affecting the vendor skew toward critical-severity outcomes and frequently acquire public exploit code, with the recurring exposure centered on deserialization of untrusted data, code injection, resource-exhaustion, and integrity-checking gaps that are inherent to model-loading and dynamic-execution patterns in machine-learning frameworks. Defenders should treat model provenance and input validation in Keras pipelines as a priority attack surface; live severity and exploitation counts are shown alongside this summary.

FAUCET AI Generated
14
Total CVEs
More Total CVEs than 94% of tracked vendors
4.7
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
8.1
Avg CVSS Score
Higher Avg CVSS Score than 79% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Keras over time

Volume of CVEsAvg CVSS Base Score
First CVE
Apr 16, 2024
2 years ago
Most Recent CVE
Jul 3, 2026
21 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (14 CVEs).

14 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-1550CRITICAL
The Keras Model.load_model function permits arbitrary code execution, even with safe_mode=True, through a manually constructed, malicious .keras archive. By altering the config.jso
Mar 11, 20259.852NOYES
CVE-2026-12481CRITICAL
A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` layer. Specifically, the `_raise_
Jul 3, 20269.842NONO
CVE-2026-11816HIGH
Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils.py`. The functions `filter_safe_t
Jun 11, 20268.134NONO
CVE-2026-1462HIGH
A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` m
Apr 13, 20267.833NONO
CVE-2025-49655CRITICAL
Deserialization of untrusted data can occur in versions of the Keras framework running versions 3.11.0 up to but not including 3.11.3, enabling a maliciously uploaded Keras file co
Oct 17, 20259.833NONO
CVE-2026-0897HIGH
Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a
Jan 15, 20267.530NONO
CVE-2026-1669HIGH
Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files
Feb 11, 20267.529NONO
CVE-2025-12060HIGH
The keras.utils.get_file API in Keras, when used with the extract=True option for tar archives, is vulnerable to a path traversal attack. The utility uses Python's tarfile.extracta
Oct 30, 20258.929NONO
CVE-2024-3660CRITICAL
A arbitrary code injection vulnerability in TensorFlow's Keras framework (<2.13) allows attackers to execute arbitrary code with the same permissions as the application using a mod
Apr 16, 20249.829NONO
CVE-2025-8747HIGH
A safe mode bypass vulnerability in the `Model.load_model` method in Keras versions 3.0.0 through 3.10.0 allows an attacker to achieve arbitrary code execution by convincing a user
Aug 11, 20257.827NONO
View all 14 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products14 CVEs
14%
57%
29%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (28.6%)
Network9 (64.3%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low13 (92.9%)
High1 (7.1%)
Unknown0 (0.0%)
User Interaction
None6 (42.9%)
Unknown0 (0.0%)
Required6 (42.9%)
Privileges Required
Low4 (28.6%)
High0 (0.0%)
None10 (71.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (14 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
1 CVE
7.1% of CVEs· 96th percentile
ExploitDB
1 CVE
7.1% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Keras.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Keras — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Keras's Products

View all 5 CNAs →

Top CWEs