REDHAT-BUG-2457856: High severity pypi/keras vulnerability

Published Apr 13, 2026
·
Updated

A vulnerability in the TFSMLayer class of the keras package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of .keras models, even when safemode=True. This bypasses the security guarantees of safemode and enables arbitrary attacker-controlled code execution during model inference under the victim's privileges. The issue arises due to the unconditional loading of external SavedModels, serialization of attacker-controlled file paths, and the lack of validation in the fromconfig() method.

Affected Software

1 affected component
pypi/keras=3.13.0

Event History

Apr 13, 2026
Data Sourced
via Red Hat·03:02 PM
DescriptionSeverityAffected Software

Frequently Asked Questions

1

What is the severity of REDHAT-BUG-2457856?

The severity of REDHAT-BUG-2457856 is classified as high with a score of 7.

2

How does REDHAT-BUG-2457856 affect the security of my application?

REDHAT-BUG-2457856 allows attacker-controlled models to be loaded despite safe_mode being enabled, compromising security.

3

What versions of the keras package are affected by REDHAT-BUG-2457856?

REDHAT-BUG-2457856 affects the keras package version 3.13.0.

4

How do I mitigate the risks associated with REDHAT-BUG-2457856?

To mitigate REDHAT-BUG-2457856, upgrade to a version of keras that has fixed the vulnerability.

5

What is the impact of REDHAT-BUG-2457856 on TensorFlow models?

REDHAT-BUG-2457856 enables the loading of attacker-controlled TensorFlow SavedModels, which can lead to arbitrary code execution.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203