Keras is a widely used deep-learning library that sits as a critical dependency across machine-learning and data-science workflows, despite maintaining a very focused product footprint. Vulnerabilities affecting the vendor skew toward critical-severity outcomes and frequently acquire public exploit code, with the recurring exposure centered on deserialization of untrusted data, code injection, resource-exhaustion, and integrity-checking gaps that are inherent to model-loading and dynamic-execution patterns in machine-learning frameworks. Defenders should treat model provenance and input validation in Keras pipelines as a priority attack surface; live severity and exploitation counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Keras over time
Signals from CVEs in this vendor scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-1550CRITICAL The Keras Model.load_model function permits arbitrary code execution, even with safe_mode=True, through a manually constructed, malicious .keras archive. By altering the config.jso | Mar 11, 2025 | 9.8 | 52 | NO | YES |
CVE-2026-12481CRITICAL A vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` layer. Specifically, the `_raise_ | Jul 3, 2026 | 9.8 | 42 | NO | NO |
CVE-2026-11816HIGH Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils.py`. The functions `filter_safe_t | Jun 11, 2026 | 8.1 | 34 | NO | NO |
CVE-2026-1462HIGH A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` m | Apr 13, 2026 | 7.8 | 33 | NO | NO |
CVE-2025-49655CRITICAL Deserialization of untrusted data can occur in versions of the Keras framework running versions 3.11.0 up to but not including 3.11.3, enabling a maliciously uploaded Keras file co | Oct 17, 2025 | 9.8 | 33 | NO | NO |
CVE-2026-0897HIGH Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a | Jan 15, 2026 | 7.5 | 30 | NO | NO |
CVE-2026-1669HIGH Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files | Feb 11, 2026 | 7.5 | 29 | NO | NO |
CVE-2025-12060HIGH The keras.utils.get_file API in Keras, when used with the extract=True option for tar archives, is vulnerable to a path traversal attack. The utility uses Python's tarfile.extracta | Oct 30, 2025 | 8.9 | 29 | NO | NO |
CVE-2024-3660CRITICAL A arbitrary code injection vulnerability in TensorFlow's Keras framework (<2.13) allows attackers to execute arbitrary code with the same permissions as the application using a mod | Apr 16, 2024 | 9.8 | 29 | NO | NO |
CVE-2025-8747HIGH A safe mode bypass vulnerability in the `Model.load_model` method in Keras versions 3.0.0 through 3.10.0 allows an attacker to achieve arbitrary code execution by convincing a user | Aug 11, 2025 | 7.8 | 27 | NO | NO |
Signals from CVEs in this vendor scope (14 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Keras.
Media articles that mention a CVE ID that affects a product developed by Keras — matched by CVE ID, not by vendor name.