<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Fri, 02 Oct 2026 22:00:08 +0000</lastBuildDate>
    <item>
      <title>certfr-2026-avi-0556 — De multiples vulnérabilités ont été découvertes dans les produits VMware. Elles permettent à un attaquant de provoquer…</title>
      <link>https://cve.radiocsirt.org/vuln/certfr-2026-avi-0556</link>
      <description>certfr-2026-avi-0556</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/certfr-2026-avi-0556</guid>
    </item>
    <item>
      <title>EUVD-2026-337592</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-337592</link>
      <description>EUVD-2026-337592</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-337592</guid>
    </item>
    <item>
      <title>fkie_cve-2026-0897</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2026-0897</link>
      <description>&lt;p&gt;Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and a crash of the Python interpreter via a crafted .keras archive containing a valid model.weights.h5 file whose dataset declares an extremely large shape.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and a crash of the Python interpreter via a crafted .keras archive containing a valid model.weights.h5 file whose dataset declares an extremely large shape.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2026-0897</guid>
    </item>
    <item>
      <title>GHSA-mgx6-5cf9-rr43 — Keras vulnerable to DoS via Malicious .keras Model (HDF5 Shape Bomb Causes Petabyte Allocation in KerasFileEditor)</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-mgx6-5cf9-rr43</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: keras&lt;/p&gt;
&lt;p&gt;### Summary
Keras’s model loader (KerasFileEditor) unsafely loads user-supplied .keras model files containing HDF5-based weight files without performing any validation on HDF5 dataset metadata. An attacker can craft a .keras archive containing a valid model.weights.h5 file whose dataset declares an extremely large shape (e.g. (50_000_000, 50_000_000)), but stores only a few bytes. The .keras file remains small (100–400 KB) because HDF5 with gzip compression stores minimal data. During model loading, 
Keras executes:
`python
result[key] = value[()]   # loads entire dataset into memory`
value[()] instructs h5py to allocate RAM proportional to the dataset’s declared shape – in this case 8.88 PiB of memory. This results in: Immediate memory exhaustion Python / TensorFlow crashes Jupyter kernel kill System instability Full Denial of Service on any workload that processes untrusted .keras models This allows an attacker to crash any environment or pipeline that loads .keras models, including MLOps backends, training services, model upload endpoints, or automated pipelines.
### Proof of Concept
```
// PoC.py
import zipfile
import io
import h5py
import numpy as np
from keras.saving import KerasFileEditor&lt;/p&gt;
&lt;p&gt;# Create a malicious .keras model containing a massive HDF5 shape bomb
def create_malicious_keras(path=&amp;#34;bomb.keras&amp;#34;):
    hdf5_bytes = io.BytesIO()&lt;/p&gt;
&lt;p&gt;# Create an HDF5 file with a huge declared dataset shape
    with h5py.File(hdf5_bytes, &amp;#34;w&amp;#34;) as f:
        d = f.create_dataset(…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: keras&lt;/p&gt;
&lt;p&gt;### Summary
Keras’s model loader (KerasFileEditor) unsafely loads user-supplied .keras model files containing HDF5-based weight files without performing any validation on HDF5 dataset metadata. An attacker can craft a .keras archive containing a valid model.weights.h5 file whose dataset declares an extremely large shape (e.g. (50_000_000, 50_000_000)), but stores only a few bytes. The .keras file remains small (100–400 KB) because HDF5 with gzip compression stores minimal data. During model loading, 
Keras executes:
`python
result[key] = value[()]   # loads entire dataset into memory`
value[()] instructs h5py to allocate RAM proportional to the dataset’s declared shape – in this case 8.88 PiB of memory. This results in: Immediate memory exhaustion Python / TensorFlow crashes Jupyter kernel kill System instability Full Denial of Service on any workload that processes untrusted .keras models This allows an attacker to crash any environment or pipeline that loads .keras models, including MLOps backends, training services, model upload endpoints, or automated pipelines.
### Proof of Concept
```
// PoC.py
import zipfile
import io
import h5py
import numpy as np
from keras.saving import KerasFileEditor&lt;/p&gt;
&lt;p&gt;# Create a malicious .keras model containing a massive HDF5 shape bomb
def create_malicious_keras(path=&amp;#34;bomb.keras&amp;#34;):
    hdf5_bytes = io.BytesIO()&lt;/p&gt;
&lt;p&gt;# Create an HDF5 file with a huge declared dataset shape
    with h5py.File(hdf5_bytes, &amp;#34;w&amp;#34;) as f:
        d = f.create_dataset(…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-mgx6-5cf9-rr43</guid>
    </item>
    <item>
      <title>msrc_CVE-2026-0897 — Denial of Service in Keras via Excessive Memory Allocation in HDF5 Metadata</title>
      <link>https://cve.radiocsirt.org/vuln/msrc_cve-2026-0897</link>
      <description>msrc_CVE-2026-0897</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/msrc_cve-2026-0897</guid>
    </item>
    <item>
      <title>PYSEC-2026-73</title>
      <link>https://cve.radiocsirt.org/vuln/pysec-2026-73</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: keras&lt;/p&gt;
&lt;p&gt;Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and a crash of the Python interpreter via a crafted .keras archive containing a valid model.weights.h5 file whose dataset declares an extremely large shape.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; PyPI: keras&lt;/p&gt;
&lt;p&gt;Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and a crash of the Python interpreter via a crafted .keras archive containing a valid model.weights.h5 file whose dataset declares an extremely large shape.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/pysec-2026-73</guid>
    </item>
    <item>
      <title>RHSA-2026:3713 — Red Hat Security Advisory: RHOAI 3.3 - Red Hat OpenShift AI</title>
      <link>https://cve.radiocsirt.org/vuln/rhsa-2026:3713</link>
      <description>&lt;p&gt;github.com/containerd/containerd: containerd local privilege escalation vllm: Server Side request forgery (SSRF) in MediaConnector keras: Path Traversal Vulnerability in keras node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications php: PHP: Denial of Service via invalid character sequence in PDO PostgreSQL prepared statement transformers: code execution when processing a malicious Perceiver model file transformers: code execution when processing a malicious Transformer-XL model file diffusers: Hugging Face Diffusers: Remote Code Execution via Deserialization of Untrusted Data transformers: code execution when processing a malicious megatron_gpt2 model file accelerate: Hugging Face Accelerate: Remote Code Execution via Deserialization of Untrusted Data transformers: code execution when converting a malicious SEW model checkpoint transformers: code execution when converting a malicious SEW-D model checkpoint transformers: code execution when converting a malicious HuBERT model checkpoint transformers: code execution when processing a malicious X-CLIP model file transformers: code execution when processing a malicious GLM4 model file qs: qs: Denial of Service via improper input validation in array parsing vllm: HTTP header size limit not enforced allows Denial of Service from Unauthenticated requests runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects v…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;github.com/containerd/containerd: containerd local privilege escalation vllm: Server Side request forgery (SSRF) in MediaConnector keras: Path Traversal Vulnerability in keras node-forge: node-forge: Interpretation conflict vulnerability allows bypassing cryptographic verifications php: PHP: Denial of Service via invalid character sequence in PDO PostgreSQL prepared statement transformers: code execution when processing a malicious Perceiver model file transformers: code execution when processing a malicious Transformer-XL model file diffusers: Hugging Face Diffusers: Remote Code Execution via Deserialization of Untrusted Data transformers: code execution when processing a malicious megatron_gpt2 model file accelerate: Hugging Face Accelerate: Remote Code Execution via Deserialization of Untrusted Data transformers: code execution when converting a malicious SEW model checkpoint transformers: code execution when converting a malicious SEW-D model checkpoint transformers: code execution when converting a malicious HuBERT model checkpoint transformers: code execution when processing a malicious X-CLIP model file transformers: code execution when processing a malicious GLM4 model file qs: qs: Denial of Service via improper input validation in array parsing vllm: HTTP header size limit not enforced allows Denial of Service from Unauthenticated requests runc: opencontainers/selinux: container escape and denial of service due to arbitrary write gadgets and procfs write redirects v…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/rhsa-2026:3713</guid>
    </item>
    <item>
      <title>UBUNTU-CVE-2026-0897</title>
      <link>https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-0897</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: keras, Ubuntu:20.04:LTS: keras&lt;/p&gt;
&lt;p&gt;Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and a crash of the Python interpreter via a crafted .keras archive containing a valid model.weights.h5 file whose dataset declares an extremely large shape.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:18.04:LTS: keras, Ubuntu:20.04:LTS: keras&lt;/p&gt;
&lt;p&gt;Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and a crash of the Python interpreter via a crafted .keras archive containing a valid model.weights.h5 file whose dataset declares an extremely large shape.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ubuntu-cve-2026-0897</guid>
    </item>
  </channel>
</rss>
