CVE-2026-0897 Details
Description
Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and a crash of the Python interpreter via a crafted .keras archive containing a valid model.weights.h5 file whose dataset declares an extremely large shape.
A denial-of-service vulnerability has been identified in the HDF5 weight loading component of Google Keras, versions 3.0.0 through 3.13.0, across all platforms. This vulnerability allows remote attackers to cause memory exhaustion and crash the Python interpreter by using a specially crafted .keras archive that contains a valid model.weights.h5 file. The malicious file's dataset can declare an extremely large shape, leading to memory exhaustion.
Users can update to the latest version of Google Keras, where this vulnerability has been addressed, to mitigate this issue.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jan 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://access.redhat.com/errata/RHSA-2026:3713 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:3782 | redhat-SADP | |
| https://access.redhat.com/errata/RHSA-2026:4271 | redhat-SADP | |
| https://access.redhat.com/security/cve/CVE-2026-0897 | redhat-SADP | |
| https://bugzilla.redhat.com/show_bug.cgi?id=2430027 | redhat-SADP | |
| https://security.access.redhat.com/data/csaf/v2/vex/2026/cve-2026-0897.json | redhat-SADP | |
| https://github.com/keras-team/keras/pull/21880 | [email protected] | Issue TrackingPatch |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-770 | Allocation of Resources Without Limits or Throttling | redhat-SADP |
| CWE-770 | Allocation of Resources Without Limits or Throttling | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| keras keras | >= 3.0.0, <= 3.13.0 |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 15, 2026 | CVE Modified | redhat-SADP |
| Jun 30, 2026 | CVE Modified | redhat-SADP |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 23, 2026 | Initial Analysis | [email protected] |
| Jan 15, 2026 | New CVE Received | [email protected] |