Live data from GitHub and PyPI, updated daily.
Data last fetched: 2026-08-24
10 active CVEs reported via OSV.dev
Keras: HDF5 virtual datasets can disclose local files
Keras is vulnerable to Deserialization of Untrusted Data
The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded.
Keras has a Local File Disclosure via HDF5 External Storage During Keras Weight Loading
Arbitrary Code Execution via Crafted Keras Config for Model Loading
Keras has an untrusted deserialization vulnerability
Keras: tar extraction permits symlink-based path traversal
Keras: Lambda deserialization can bypass safe mode and execute code
Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality
keras Path Traversal vulnerability
Other AI / ML projects in the Python ecosystem worth evaluating.
Get SLA-backed support, security patches, and direct access to senior engineers for Keras — without relying on volunteer maintainers.