Launch Week Day 1: Announcing Security Design Review
25 Total advisories
25 Vulnerabilities
0 Malware

Vulnerabilities

CRITICAL 9.8
PyPI

CVE-2025-1550

CVE-2025-1550

HIGH 7.5
PyPI

CVE-2026-0897

CVE-2026-0897

HIGH 7.3
PyPI

CVE-2025-9906

CVE-2025-9906

HIGH 7.8
PyPI

CVE-2025-8747

CVE-2025-8747

MEDIUM 6.5
PyPI

CVE-2024-55459

CVE-2024-55459

UNKNOWN
PyPI

CVE-2026-0897

Keras vulnerable to DoS via Malicious .keras Model (HDF5 Shape Bomb Causes Petabyte Allocation in KerasFileEditor)

UNKNOWN
PyPI

CVE-2025-1550

Arbitrary Code Execution via Crafted Keras Config for Model Loading

UNKNOWN
PyPI

CVE-2024-55459

keras Path Traversal vulnerability

UNKNOWN
PyPI

CVE-2025-9905

The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded.

HIGH 7.3
PyPI

CVE-2025-9906

Keras is vulnerable to Deserialization of Untrusted Data

HIGH 8.8
PyPI

CVE-2025-8747

Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality

HIGH 7.3
PyPI

CVE-2025-9905

CVE-2025-9905

HIGH 8.8
PyPI

CVE-2026-1462

Keras has an untrusted deserialization vulnerability

UNKNOWN
PyPI

CVE-2026-0897

Duplicate Advisory: Google Keras Allocates Resources Without Limits or Throttling in the HDF5 weight loading component

UNKNOWN
PyPI

CVE-2025-12058

Keras is vulnerable to arbitrary local file loading and Server-Side Request Forgery

HIGH 7.1
PyPI

CVE-2026-1669

Keras has a Local File Disclosure via HDF5 External Storage During Keras Weight Loading

UNKNOWN
PyPI

CVE-2026-1669

Duplicate Advisory: Keras vulnerable to arbitrary file read in the model loading mechanism (HDF5 integration)

UNKNOWN
PyPI

GHSA-28jp-44vh-q42h

Duplicate Advisory: Keras keras.utils.get_file API is vulnerable to a path traversal attack

CRITICAL 9.8
PyPI

CVE-2025-12060

Keras Directory Traversal Vulnerability

HIGH 8.0
PyPI

GHSA-9g7v-8wxv-mwxp

Duplicate Advisory: Keras keras.utils.get_file API is vulnerable to a path traversal attack

CRITICAL 9.8
PyPI

CVE-2025-49655

Keras framework vulnerable to deserialization of untrusted data

UNKNOWN
PyPI

GHSA-77wq-646f-jrm2

Duplicate Advisory: The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded.

UNKNOWN
PyPI

GHSA-pwq7-2gvj-vg9v

Duplicate Advisory: Keras safe mode bypass vulnerability

UNKNOWN
PyPI

GHSA-5478-v2w6-c6q7

Duplicate Advisory: Keras arbitrary code execution vulnerability

CRITICAL 9.8
PyPI

CVE-2024-3660

Keras code injection vulnerability

Ready to move

Start Securing

Free, no credit card | First findings in minutes