CVE-2026-0897Allocation of Resources Without Limits or Throttling in Keras

Severity
7.1HIGHNVD
EPSS
0.0%
top 91.44%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJan 15

Description

Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and a crash of the Python interpreter via a crafted .keras archive containing a valid model.weights.h5 file whose dataset declares an extremely large shape.

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N

Affected Packages3 packages

CVEListV5google/keras3.0.03.13.0
PyPIkeras/keras3.0.03.12.1+1
NVDkeras/keras3.0.03.13.0

Patches

🔴Vulnerability Details

4
OSV
Google Keras Allocates Resources Without Limits or Throttling in the HDF5 weight loading component2026-01-15
GHSA
Google Keras Allocates Resources Without Limits or Throttling in the HDF5 weight loading component2026-01-15
CVEList
Denial of Service in Keras via Excessive Memory Allocation in HDF5 Metadata2026-01-15
OSV
CVE-2026-0897: Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 32026-01-15

📋Vendor Advisories

2
Red Hat
Keras: Keras: Denial of Service via crafted HDF5 weight loading file2026-01-15
Debian
CVE-2026-0897: keras - Allocation of Resources Without Limits or Throttling in the HDF5 weight loading ...2026

🕵️Threat Intelligence

1
Wiz
CVE-2026-0897 Impact, Exploitability, and Mitigation Steps | Wiz
CVE-2026-0897 — Keras vulnerability | cvebase