{"id":"UBUNTU-CVE-2026-12480","details":"Keras versions up to and including 3.13.2 are vulnerable to an arbitrary HDF5 file read due to an incomplete fix for CVE-2026-1669. The vulnerability resides in the `H5IOStore._verify_dataset()` and `file_editor.py` methods, which fail to check the `dataset.is_virtual` property of HDF5 datasets. This allows an attacker to craft a malicious `.keras` model archive or `.h5` weights file containing a Virtual Dataset (VDS) that references external HDF5 files on the victim's filesystem. When the victim loads the model using `keras.models.load_model()` or `keras.saving.load_model()`, the external file is transparently read, leading to potential information disclosure. Fixed in versions 3.12.2 and 3.14.1.","modified":"2026-07-09T15:15:45Z","published":"2026-07-01T17:16:00Z","upstream":["CVE-2026-12480"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-12480"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-12480"},{"type":"REPORT","url":"https://github.com/keras-team/keras/commit/d5a88bdb137c0d3039b8f4bbbe8c7099925cc10c"},{"type":"REPORT","url":"https://huntr.com/bounties/1875d257-5b03-4a69-ac70-e98653fa12c7"}],"affected":[{"package":{"name":"keras","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/keras?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.0.7-2","2.1.1-1"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-keras","binary_version":"2.1.1-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-12480.json"}},{"package":{"name":"keras","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/keras?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.2.4-1"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-keras","binary_version":"2.2.4-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-12480.json"}}],"schema_version":"1.7.5","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N"},{"type":"Ubuntu","score":"medium"}]}