<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-02T21:15:43.015133+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2026-08021</id>
    <title>bdu:2026-08021</title>
    <updated>2026-10-02T21:15:43.026441+00:00</updated>
    <content>bdu:2026-08021</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2026-08021"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-272077</id>
    <title>EUVD-2026-272077</title>
    <updated>2026-10-02T21:15:43.026485+00:00</updated>
    <content>EUVD-2026-272077</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-272077"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-9906</id>
    <title>fkie_cve-2025-9906</title>
    <updated>2026-10-02T21:15:43.026500+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p>The Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True.</p>
<p>One can create a specially crafted .keras model archive that, when loaded via Model.load_model, will trigger arbitrary code to be executed. This is achieved by crafting a special config.json (a file within the .keras archive) that will invoke keras.config.enable_unsafe_deserialization() to disable safe mode. Once safe mode is disable, one can use the Lambda layer feature of keras, which allows arbitrary Python code in the form of pickled code. Both can appear in the same archive. Simply the keras.config.enable_unsafe_deserialization() needs to appear first in the archive and the Lambda with arbitrary code needs to be second.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-9906"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-36fq-jgmw-4r9c</id>
    <title>GHSA-36fq-jgmw-4r9c — Keras is vulnerable to Deserialization of Untrusted Data</title>
    <updated>2026-10-02T21:15:43.026535+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: keras</p>
<p>### Arbitrary Code Execution in Keras</p>
<p>Keras versions prior to 3.11.0 allow for arbitrary code execution when loading a crafted `.keras` model archive, even when `safe_mode=True`.</p>
<p>The issue arises because the archive’s `config.json` is parsed before layer deserialization. This can invoke `keras.config.enable_unsafe_deserialization()`, effectively disabling safe mode from within the loading process itself. An attacker can place this call first in the archive and then include a `Lambda` layer whose function is deserialized from a pickle, leading to the execution of attacker-controlled Python code as soon as a victim loads the model file.</p>
<p>Exploitation requires a user to open an untrusted model; no additional privileges are needed. The fix in version 3.11.0 enforces safe-mode semantics *before* reading any user-controlled configuration and prevents the toggling of unsafe deserialization via the config file.</p>
<p>**Affected versions:** &lt; 3.11.0
**Patched version:** 3.11.0</p>
<p>It is recommended to upgrade to version 3.11.0 or later and to avoid opening untrusted model files.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-36fq-jgmw-4r9c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/msrc_cve-2025-9906</id>
    <title>msrc_CVE-2025-9906 — Arbitrary Code execution in Keras Safe Mode</title>
    <updated>2026-10-02T21:15:43.026572+00:00</updated>
    <content>msrc_CVE-2025-9906</content>
    <link href="https://cve.radiocsirt.org/vuln/msrc_cve-2025-9906"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2025-76</id>
    <title>PYSEC-2025-76</title>
    <updated>2026-10-02T21:15:43.026589+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: keras</p>
<p>The Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True.</p>
<p>One can create a specially crafted .keras model archive that, when loaded via Model.load_model, will trigger arbitrary code to be executed. This is achieved by crafting a special config.json (a file within the .keras archive) that will invoke keras.config.enable_unsafe_deserialization() to disable safe mode. Once safe mode is disable, one can use the Lambda layer feature of keras, which allows arbitrary Python code in the form of pickled code. Both can appear in the same archive. Simply the keras.config.enable_unsafe_deserialization() needs to appear first in the archive and the Lambda with arbitrary code needs to be second.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2025-76"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:23531</id>
    <title>RHSA-2025:23531 — Red Hat Security Advisory: RHOAI 2.25.1 - Red Hat OpenShift AI</title>
    <updated>2026-10-02T21:15:43.026612+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>keras: Arbitary Code execution in Keras load_model() keras: Arbitrary Code execution in Keras Safe Mode keras: Keras Path Traversal Vulnerability keras: Path Traversal Vulnerability in keras golang.org/x/crypto/ssh/agent: golang.org/x/crypto/ssh/agent: SSH client panic due to unexpected SSH_AGENT_SUCCESS keras: Keras deserialization of untrusted data aiohttp: AIOHTTP HTTP Request/Response Smuggling vllm: VLLM deserialization vulnerability leading to DoS and potential RCE ray: Ray is vulnerable to RCE via Safari &amp; Firefox Browsers through DNS Rebinding Attack starlette: Starlette DoS via Range header merging glob: glob: Command Injection Vulnerability via Malicious Filenames mcp: DNS Rebinding Protection Disabled by Default in Model Context Protocol Python SDK</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:23531"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-9906</id>
    <title>UBUNTU-CVE-2025-9906</title>
    <updated>2026-10-02T21:15:43.026641+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:18.04:LTS: keras, Ubuntu:20.04:LTS: keras</p>
<p>The Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True. One can create a specially crafted .keras model archive that, when loaded via Model.load_model, will trigger arbitrary code to be executed. This is achieved by crafting a special config.json (a file within the .keras archive) that will invoke keras.config.enable_unsafe_deserialization() to disable safe mode. Once safe mode is disable, one can use the Lambda layer feature of keras, which allows arbitrary Python code in the form of pickled code. Both can appear in the same archive. Simply the keras.config.enable_unsafe_deserialization() needs to appear first in the archive and the Lambda with arbitrary code needs to be second.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2025-9906"/>
  </entry>
</feed>
