{"id":"CVE-2026-12570","summary":"Denial of Service via HDF5 Shape Bomb in keras.models.load_model() in keras-team/keras","details":"A vulnerability in keras-team/keras versions \u003c= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.__getitem__ method in keras/src/saving/saving_lib.py does not validate the shape or size of datasets, leading to unbounded memory allocation. A specially crafted .keras file can exploit this flaw to trigger an out-of-memory (OOM) condition, causing the process to be terminated (exit code 137). This issue bypasses the fix for CVE-2026-0897, which only addressed a similar vulnerability in KerasFileEditor. The attack vector includes poisoned models from public repositories or malicious model registries, posing a risk to machine learning pipelines that process untrusted models.","modified":"2026-08-12T04:16:24.739187996Z","published":"2026-08-10T06:29:56.111Z","database_specific":{"unresolved_ranges":[{"extracted_events":[{"fixed":"3.12.3, 3.15.0"}],"source":"AFFECTED_FIELD"}],"cna_assigner":"@huntr_ai","cwe_ids":["CWE-770"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/12xxx/CVE-2026-12570.json"},"references":[{"type":"WEB","url":"https://huntr.com/bounties/a064f475-780a-409a-82f7-678512f27ad8"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/12xxx/CVE-2026-12570.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-12570"},{"type":"FIX","url":"https://github.com/keras-team/keras/commit/4933ea4a5b3fcc24ceacdc276f5bb5dfbd06756c"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/keras-team/keras","events":[{"introduced":"0"},{"fixed":"4933ea4a5b3fcc24ceacdc276f5bb5dfbd06756c"}],"database_specific":{"source":"REFERENCES"}}],"versions":["v3.14.0","v3.12.0","v3.11.0","v3.10.0","v3.9.0","v3.8.0","v3.7.0","v3.6.0","v3.5.0","v3.4.1","v3.4.0","v3.3.3","v3.3.2","v3.3.1","v3.3.0","v3.2.1","v3.2.0","v3.1.1","v3.1.0","v3.0.5","v3.0.4","v3.0.3","v3.0.2","v3.0.1","v3.0.0","v2.9.0-rc0","v2.8.0-rc0","v2.7.0-rc0","v2.6.0-rc0","2.4.0","2.3.1","2.3.0","2.2.4","2.2.3","2.2.2","2.2.1","2.2.0","2.1.6","2.1.5","2.1.4","2.1.3","2.1.2","2.1.1","2.1.0","2.0.9","2.0.8","2.0.7","2.0.6","2.0.5","2.0.4","2.0.3","2.0.2","2.0.1","2.0.0","1.2.0","1.1.1","1.1.0","1.0.8","1.0.7","1.0.6","1.0.5","1.0.4","1.0.3","1.0.2","1.0.1","1.0.0","0.3.2","0.3.1","0.3.0","0.2.0","0.1.3","0.1.2","0.1.1","0.1.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-12570.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"}]}