REDHAT-BUG-2439205: High severity Keras Keras vulnerability
Published Feb 11, 2026
·Updated
Arbitrary file read in the model loading mechanism (HDF5 integration) in Keras versions 3.0.0 through 3.13.1 on all supported platforms allows a remote attacker to read local files and disclose sensitive information via a crafted .keras model file utilizing HDF5 external dataset references.
Affected Software
1 affected component
Keras Keras>=3.0.0<=3.13.1
Event History
Feb 11, 2026
Data Sourced
via Red Hat·11:01 PM
DescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of REDHAT-BUG-2439205?
The severity of REDHAT-BUG-2439205 is classified as high with a score of 7.
2
How do I fix REDHAT-BUG-2439205?
To fix REDHAT-BUG-2439205, update Keras to version 3.13.2 or later where the vulnerability has been addressed.
3
What impact does REDHAT-BUG-2439205 have on my system?
REDHAT-BUG-2439205 allows a remote attacker to read local files, potentially disclosing sensitive information.
4
Which versions of Keras are affected by REDHAT-BUG-2439205?
Keras versions 3.0.0 through 3.13.1 are affected by REDHAT-BUG-2439205.
5
Can REDHAT-BUG-2439205 be exploited remotely?
Yes, REDHAT-BUG-2439205 can be exploited remotely through a crafted .keras model file.