๐Ÿ” CVE Alert

CVE-2026-9335

MEDIUM 6.5

Improper Handling of HDF5 ExternalLinks in keras-team/keras

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalLinks. The `KerasFileEditor` and `keras.saving.load_weights` functions bypass the `safe_get_h5_group` and `safe_get_h5_dataset` helpers, which are designed to reject ExternalLinks and SoftLinks. This results in automatic dereferencing of links to external HDF5 files, enabling attackers to disclose sensitive data from the victim's local filesystem. Specifically, `KerasFileEditor` extracts attributes and datasets from linked files into its internal structures, while `keras.saving.load_weights` loads weights from linked files into the user's model. This issue can be exploited by providing a malicious `.h5`, `.weights.h5`, or `.keras` file containing ExternalLinks.

CWE CWE-22
Vendor keras-team
Product keras-team/keras
Published Aug 2, 2026
Stay Ahead of the Next One

Get instant alerts for keras-team keras-team/keras

Be the first to know when new medium vulnerabilities affecting keras-team keras-team/keras are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Affected Versions

keras-team / keras-team/keras
unspecified < 3.12.3, 3.15.0

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
huntr.com: https://huntr.com/bounties/876a7226-5428-4a66-9d05-232461120db5 github.com: https://github.com/keras-team/keras/commit/23370f16b0ab9a200f7550a34e54a3ceab74ba0e