Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-xfhx-r7ww-5995 | Google Keras Allocates Resources Without Limits or Throttling in the HDF5 weight loading component |
Github GHSA |
GHSA-mgx6-5cf9-rr43 | Keras vulnerable to DoS via Malicious .keras Model (HDF5 Shape Bomb Causes Petabyte Allocation in KerasFileEditor) |
Fri, 23 Jan 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:keras:keras:*:*:*:*:*:*:*:* | |
| Metrics |
cvssV3_1
|
cvssV3_1
|
Fri, 16 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Keras
Keras keras |
|
| Vendors & Products |
Keras
Keras keras |
Fri, 16 Jan 2026 00:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Thu, 15 Jan 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 15 Jan 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and a crash of the Python interpreter via a crafted .keras archive containing a valid model.weights.h5 file whose dataset declares an extremely large shape. | |
| Title | Denial of Service in Keras via Excessive Memory Allocation in HDF5 Metadata | |
| Weaknesses | CWE-770 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Google
Published:
Updated: 2026-01-15T16:38:18.772Z
Reserved: 2026-01-13T15:59:54.703Z
Link: CVE-2026-0897
Updated: 2026-01-15T16:38:08.610Z
Status : Analyzed
Published: 2026-01-15T14:16:26.890
Modified: 2026-01-23T18:35:49.733
Link: CVE-2026-0897
OpenCVE Enrichment
Updated: 2026-04-18T06:15:15Z
Github GHSA