CVE-2026-12480
published 2026-07-01CVE-2026-12480: Keras versions up to and including 3.13.2 are vulnerable to an arbitrary HDF5 file read due to an incomplete fix for CVE-2026-1669. The vulnerability resides…
PriorityP430medium5.5CVSS 3.0
AVLACLPRNUIRSUCHINAN
EPSS
0.13%
2.8th percentile
Keras versions up to and including 3.13.2 are vulnerable to an arbitrary HDF5 file read due to an incomplete fix for CVE-2026-1669. The vulnerability resides in the `H5IOStore._verify_dataset()` and `file_editor.py` methods, which fail to check the `dataset.is_virtual` property of HDF5 datasets. This allows an attacker to craft a malicious `.keras` model archive or `.h5` weights file containing a Virtual Dataset (VDS) that references external HDF5 files on the victim's filesystem. When the victim loads the model using `keras.models.load_model()` or `keras.saving.load_model()`, the external file is transparently read, leading to potential information disclosure. Fixed in versions 3.12.2 and 3.14.1.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| keras-team | keras-team_keras | >= unspecified < 3.12.2, 3.14.1 | 3.12.2, 3.14.1 |
| keras | keras | >= 0 < 3.12.3 | 3.12.3 |
| keras | keras | >= 3.13.0 < 3.15.0 | 3.15.0 |
| rhoai | odh-kserve-agent-rhel9 | — | — |
| rhoai | odh-kserve-controller-rhel9 | — | — |
| rhoai | odh-kserve-router-rhel9 | — | — |
| rhoai | odh-kserve-storage-initializer-rhel9 | — | — |
| rhoai | odh-modelmesh-runtime-adapter-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-tensorflow-cuda-py312-rhel9 | — | — |
| rhoai | odh-pipeline-runtime-tensorflow-rocm-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-tensorflow-cuda-py312-rhel9 | — | — |
| rhoai | odh-workbench-jupyter-tensorflow-rocm-py312-rhel9 | — | — |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
ghsa7.5HIGH
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
Keras versions up to and including 3.13.2 are vulnerable to an arbitrary HDF5 file read due to an incomplete fix for CVE-2026-1669.
ghsa_unreviewed·2026-07-01·CVSS 7.5
CVE-2026-12480 [HIGH] CWE-73 Keras versions up to and including 3.13.2 are vulnerable to an arbitrary HDF5 file read due to an incomplete fix for CVE-2026-1669.
Keras versions up to and including 3.13.2 are vulnerable to an arbitrary HDF5 file read due to an incomplete fix for CVE-2026-1669. The vulnerability resides in the `H5IOStore._verify_dataset()` and `file_editor.py` methods, which fail to check the `dataset.is_virtual` property of HDF5 datasets. This allows an attacker to craft a malicious `.keras` model archive or `.h5` weights file containing a Virtual Dataset (VDS) that references external HDF5 files on the victim's filesystem. When the victim loads the model using `keras.models.load_model()` or `keras.saving.load_model()`, the external file is transparently read, leading to potential information disclosure. Fixed in versions 3.12.2 and 3.14.1.
VulDB
keras-team keras up to 3.12.1/3.14.0 file_editor.py H5IOStore._verify_dataset file inclusion
vuldb·2026-07-01·CVSS 5.5
CVE-2026-12480 [MEDIUM] keras-team keras up to 3.12.1/3.14.0 file_editor.py H5IOStore._verify_dataset file inclusion
A vulnerability was found in keras-team keras up to 3.12.1/3.14.0. It has been rated as problematic. This affects the function H5IOStore._verify_dataset of the file file_editor.py. The manipulation leads to file inclusion.
This vulnerability is documented as CVE-2026-12480. The attack needs to be performed locally. There is not any exploit available.
Upgrading the affected component is advised.
GHSA
Keras: HDF5 virtual datasets can disclose local files
ghsa·2026-07-01·CVSS 7.5
CVE-2026-12480 [HIGH] CWE-73 Keras: HDF5 virtual datasets can disclose local files
Keras: HDF5 virtual datasets can disclose local files
Keras versions up to and including 3.13.2 are vulnerable to an arbitrary HDF5 file read due to an incomplete fix for CVE-2026-1669. The vulnerability resides in the `H5IOStore._verify_dataset()` and `file_editor.py` methods, which fail to check the `dataset.is_virtual` property of HDF5 datasets. This allows an attacker to craft a malicious `.keras` model archive or `.h5` weights file containing a Virtual Dataset (VDS) that references external HDF5 files on the victim's filesystem. When the victim loads the model using `keras.models.load_model()` or `keras.saving.load_model()`, the external file is transparently read, leading to potential information disclosure. Fixed in versions 3.12.3 and 3.15.0.
Red Hat
keras: Keras: Information disclosure via malicious model archive with Virtual Dataset
vendor_redhat·2026-07-01·CVSS 5.5
CVE-2026-12480 [MEDIUM] CWE-22 keras: Keras: Information disclosure via malicious model archive with Virtual Dataset
keras: Keras: Information disclosure via malicious model archive with Virtual Dataset
Keras versions up to and including 3.13.2 are vulnerable to an arbitrary HDF5 file read due to an incomplete fix for CVE-2026-1669. The vulnerability resides in the `H5IOStore._verify_dataset()` and `file_editor.py` methods, which fail to check the `dataset.is_virtual` property of HDF5 datasets. This allows an attacker to craft a malicious `.keras` model archive or `.h5` weights file containing a Virtual Dataset (VDS) that references external HDF5 files on the victim's filesystem. When the victim loads the model using `keras.models.load_model()` or `keras.saving.load_model()`, the external file is transparently read, leading to potential information disclosure. Fixed in versions 3.12.2 and 3.14.1.
A fla
No detection rules found.
No public exploits indexed.
2026-07-01
Published