PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-12570 keras-team CVE debrief

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T07:16:44.370Z and has not been modified since then. This vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.__getitem__ method in keras/src/saving/saving_lib.py does not validate the shape or size of datasets, leading to unbounded memory allocation. A specially crafted .keras file can exploit this flaw to trigger an out-of-memory (OOM) condition, causing the process to be terminated (exit code 137). This issue bypasses the fix for CVE-2026-0897, which only addressed a similar vulnerability in KerasFileEditor. The attack vector includes poisoned models from public repositories or malicious model registries, posing a risk to machine learning pipelines that process untrusted models.

Vendor
keras-team
Product
keras-team/keras
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-10
Original CVE updated
2026-08-10
Advisory published
2026-08-10
Advisory updated
2026-08-10

Who should care

Organizations using keras-team/keras for machine learning tasks, especially those processing untrusted models from public repositories or malicious model registries, should prioritize model validation and memory safety. Security teams and vulnerability management teams should review and implement compensating controls for exposed systems. Platform operators and administrators should monitor for suspicious model loading activity and consider alternative model formats or validation mechanisms.

Technical summary

A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.__getitem__ method in keras/src/saving/saving_lib.py does not validate the shape or size of datasets, leading to unbounded memory allocation. This issue bypasses the fix for CVE-2026-0897. Model validation and memory safety are crucial to mitigate potential DoS attacks.

Defensive priority

Organizations using keras-team/keras versions <= 3.15.0 should prioritize model validation and memory safety to mitigate potential DoS attacks.

Recommended defensive actions

  • Validate the integrity of .keras model files before loading them.
  • Implement memory safety checks to prevent unbounded memory allocation.
  • Monitor for suspicious model loading activity.
  • Consider using alternative model formats or validation mechanisms.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.

Evidence notes

The H5IOStore.__getitem__ method in keras/src/saving/saving_lib.py does not validate the shape or size of datasets, leading to unbounded memory allocation. A specially crafted .keras file can exploit this flaw to trigger an out-of-memory (OOM) condition. Organizations should verify model integrity and monitor for suspicious activity. Evidence limits suggest cautious validation of untrusted models.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T07:16:44.370Z and has not been modified since then.