REDHAT-BUG-2430027: High severity pypi/keras vulnerability

Published Jan 15, 2026
·
Updated

Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and a crash of the Python interpreter via a crafted .keras archive containing a valid model.weights.h5 file whose dataset declares an extremely large shape.

Affected Software

1 affected component
pypi/keras>=3.0.0<=3.13.0

Event History

Jan 15, 2026
Data Sourced
via Red Hat·04:01 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2430027?

The severity of REDHAT-BUG-2430027 is classified as high with a rating of 7.

2

How does REDHAT-BUG-2430027 affect the system?

REDHAT-BUG-2430027 allows a remote attacker to cause a Denial of Service (DoS) by exploiting memory exhaustion in the HDF5 weight loading component.

3

What versions of Keras are impacted by REDHAT-BUG-2430027?

Versions from Google Keras 3.0.0 through 3.13.0 on all platforms are impacted by REDHAT-BUG-2430027.

4

How can I mitigate the risk of REDHAT-BUG-2430027?

To mitigate the risk of REDHAT-BUG-2430027, ensure that you do not load untrusted .keras archives and monitor memory usage closely.

5

What type of attack can be performed using REDHAT-BUG-2430027?

An attacker can perform a Denial of Service (DoS) attack that leads to a crash of the Python interpreter through memory exhaustion.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203