Live data from GitHub and PyPI, updated daily.
Data last fetched: 2026-05-16
10 active CVEs reported via OSV.dev
Keras is vulnerable to Deserialization of Untrusted Data
The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded.
Keras has a Local File Disclosure via HDF5 External Storage During Keras Weight Loading
Arbitrary Code Execution via Crafted Keras Config for Model Loading
Keras has an untrusted deserialization vulnerability
Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality
keras Path Traversal vulnerability
Keras framework vulnerable to deserialization of untrusted data
Keras Directory Traversal Vulnerability
Keras vulnerable to DoS via Malicious .keras Model (HDF5 Shape Bomb Causes Petabyte Allocation in KerasFileEditor)
Other AI / ML projects in the Python ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for Keras — without relying on volunteer maintainers.
Talk to an Expert →