AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-12570

MEDIUM · CVSS 5.5 EPSS 0.13% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-10 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

The vulnerability in Keras versions up to 3.15.0 allows for a denial of service (DoS) attack through the loading of malicious .keras model files, which can lead to unbounded memory allocation and subsequent out-of-memory (OOM) conditions. This issue specifically affects machine learning pipelines that utilize untrusted models, making it critical for developers and organizations using Keras in production environments to prioritize mitigation efforts. Users should be particularly cautious when loading models from public repositories or unverified sources.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-12570
Severity
MEDIUM
CVSS
5.5
EPSS
0.13%

Original NVD Description

A vulnerability in keras-team/keras versions <= 3.15.0 allows for a denial of service (DoS) attack when loading malicious .keras model files via the keras.models.load_model() function. The H5IOStore.__getitem__ method in keras/src/saving/saving_lib.py does not validate the shape or size of datasets, leading to unbounded memory allocation. A specially crafted .keras file can exploit this flaw to trigger an out-of-memory (OOM) condition, causing the process to be terminated (exit code 137). This issue bypasses the fix for CVE-2026-0897, which only addressed a similar vulnerability in KerasFileEditor. The attack vector includes poisoned models from public repositories or malicious model registries, posing a risk to machine learning pipelines that process untrusted models.