{"id":"AZL-92027","summary":"CVE-2026-12480 affecting package keras 3.3.3-7","details":"Keras versions up to and including 3.13.2 are vulnerable to an arbitrary HDF5 file read due to an incomplete fix for CVE-2026-1669. The vulnerability resides in the `H5IOStore._verify_dataset()` and `file_editor.py` methods, which fail to check the `dataset.is_virtual` property of HDF5 datasets. This allows an attacker to craft a malicious `.keras` model archive or `.h5` weights file containing a Virtual Dataset (VDS) that references external HDF5 files on the victim's filesystem. When the victim loads the model using `keras.models.load_model()` or `keras.saving.load_model()`, the external file is transparently read, leading to potential information disclosure. Fixed in versions 3.12.2 and 3.14.1.","modified":"2026-09-01T05:28:09Z","published":"2026-07-01T17:16:19Z","upstream":["CVE-2026-12480"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12480"}],"affected":[{"package":{"name":"keras","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/keras"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"last_affected":"3.3.3-7"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-92027.json"}}],"schema_version":"1.9.0"}