{"id":"UBUNTU-CVE-2026-12570","details":"A vulnerability in keras-team/keras versions \u003c= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.__getitem__ method in keras/src/saving/saving_lib.py does not validate the shape or size of datasets, leading to unbounded memory allocation. A specially crafted .keras file can exploit this flaw to trigger an out-of-memory (OOM) condition, causing the process to be terminated (exit code 137). This issue bypasses the fix for CVE-2026-0897, which only addressed a similar vulnerability in KerasFileEditor. The attack vector includes poisoned models from public repositories or malicious model registries, posing a risk to machine learning pipelines that process untrusted models.","modified":"2026-08-13T03:00:46.349514839Z","published":"2026-08-10T07:16:00Z","upstream":["CVE-2026-12570"],"references":[{"type":"REPORT","url":"https://ubuntu.com/security/CVE-2026-12570"},{"type":"REPORT","url":"https://www.cve.org/CVERecord?id=CVE-2026-12570"},{"type":"REPORT","url":"https://github.com/keras-team/keras/commit/4933ea4a5b3fcc24ceacdc276f5bb5dfbd06756c"},{"type":"REPORT","url":"https://huntr.com/bounties/a064f475-780a-409a-82f7-678512f27ad8"}],"affected":[{"package":{"name":"keras","ecosystem":"Ubuntu:18.04:LTS","purl":"pkg:deb/ubuntu/keras?arch=source&distro=bionic"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["1.0.7-2","2.1.1-1"],"ecosystem_specific":{"binaries":[{"binary_version":"2.1.1-1","binary_name":"python3-keras"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-12570.json"}},{"package":{"name":"keras","ecosystem":"Ubuntu:20.04:LTS","purl":"pkg:deb/ubuntu/keras?arch=source&distro=focal"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"}]}],"versions":["2.2.4-1"],"ecosystem_specific":{"binaries":[{"binary_name":"python3-keras","binary_version":"2.2.4-1"}]},"database_specific":{"source":"https://github.com/canonical/ubuntu-security-notices/blob/main/osv/cve/2026/UBUNTU-CVE-2026-12570.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H"},{"type":"Ubuntu","score":"medium"}]}