CVE-2026-0897: Keras
High severity, CVSS 7.5. EPSS: 0.3% chance of exploitation in the next 30 days.
Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and a crash of the Python interpreter via a crafted .keras archive containing a valid model.weights.h5 file whose dataset declares an extremely large shape.
Affected products
- Keras Keras: from 3.0.0, up to and including 3.13.0
Published 2026-01-15. Last modified 2026-07-15.