OSS Support Hub / AI / ML

Python AI / ML Apache-2.0 Latest: v3.14.1

Keras

Deep learning API for humans — runs on JAX, TensorFlow, and PyTorch

Project Health at a Glance

Live data from GitHub and PyPI, updated daily.

64.1K
GitHub Stars
📦
v3.14.1
Latest Release · 9 days ago
🔄
30d
Avg. Release Cadence
🐛
187
Open Issues
📅
Today
Last Commit
🔒
10
Active CVEs

Data last fetched: 2026-05-16

Known Vulnerabilities

10 active CVEs reported via OSV.dev

Keras is vulnerable to Deserialization of Untrusted Data

Published: 2025-09-19 Fixed in: 3.11.0

The Keras `Model.load_model` method **silently** ignores `safe_mode=True` and allows arbitrary code execution when a `.h5`/`.hdf5` file is loaded.

Published: 2025-09-19 Fixed in: 3.11.3

Keras has a Local File Disclosure via HDF5 External Storage During Keras Weight Loading

Published: 2026-02-18 Fixed in: 3.13.2

Arbitrary Code Execution via Crafted Keras Config for Model Loading

Published: 2025-03-11 Fixed in: 3.9.0

Keras has an untrusted deserialization vulnerability

Published: 2026-04-13 Fixed in: 3.13.2

Keras vulnerable to CVE-2025-1550 bypass via reuse of internal functionality

Published: 2025-08-12 Fixed in: 3.11.0

keras Path Traversal vulnerability

Published: 2025-01-08 No fix available

Keras framework vulnerable to deserialization of untrusted data

Published: 2025-10-17 Fixed in: 3.11.3

Keras Directory Traversal Vulnerability

Published: 2025-12-02 Fixed in: 3.12.0

Keras vulnerable to DoS via Malicious .keras Model (HDF5 Shape Bomb Causes Petabyte Allocation in KerasFileEditor)

Published: 2026-05-06 Fixed in: 3.12.1

Alternatives to Keras

Other AI / ML projects in the Python ecosystem worth evaluating.

Support Options for Keras

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for Keras — without relying on volunteer maintainers.

Talk to an Expert →