{"id":"CVE-2026-0897","summary":"Denial of Service in Keras via Excessive Memory Allocation in HDF5 Metadata","details":"Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and a crash of the Python interpreter via a crafted .keras archive containing a valid model.weights.h5 file whose dataset declares an extremely large shape.","aliases":["GHSA-mgx6-5cf9-rr43","PYSEC-2026-73"],"modified":"2026-08-12T03:51:44.341107710Z","published":"2026-01-15T14:09:53.603Z","related":["CGA-9f7m-cgx3-xx9v"],"database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/0xxx/CVE-2026-0897.json","cna_assigner":"Google","cwe_ids":["CWE-770"]},"references":[{"type":"WEB","url":"https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0897.json"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3713"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:3782"},{"type":"ADVISORY","url":"https://access.redhat.com/errata/RHSA-2026:4271"},{"type":"ADVISORY","url":"https://access.redhat.com/security/cve/CVE-2026-0897"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/0xxx/CVE-2026-0897.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-0897"},{"type":"REPORT","url":"https://bugzilla.redhat.com/show_bug.cgi?id=2430027"},{"type":"FIX","url":"https://github.com/keras-team/keras/pull/21880"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/keras-team/keras","events":[{"introduced":"9c675a9a45e5e8244163fea82efc6066722608a1"},{"last_affected":"986ff971d98e216a89fba38d48a337ed09d6dc44"}],"database_specific":{"extracted_events":[{"introduced":"3.0.0"},{"last_affected":"3.13.0"}],"source":["AFFECTED_FIELD","CPE_RANGE"],"cpe":"cpe:2.3:a:keras:keras:*:*:*:*:*:*:*:*"}}],"versions":["v3.12.0","v3.13.0","v3.11.0","v3.10.0","v3.9.0","v3.8.0","v3.7.0","v3.6.0","v3.5.0","v3.4.1","v3.4.0","v3.3.3","v3.3.2","v3.3.1","v3.3.0","v3.2.1","v3.2.0","v3.1.1","v3.1.0","v3.0.5","v3.0.4","v3.0.3","v3.0.2","v3.0.1","v3.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-0897.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N"}]}