MEDIUMCVSS 6.5Vulnerability

CVE-2026-9335

A vulnerability in keras-team/keras versions <= 3.14.0 allows arbitrary local HDF5 file content disclosure due to improper handling of HDF5 ExternalLinks. The `KerasFileEditor` and `keras.saving.load_weights` functions bypass the `safe_get_h5_group` and `safe_get_h5_dataset` helpers, which are designed to reject ExternalLinks and SoftLinks. This results in automatic dereferencing of links to external HDF5 files, enabling attackers to disclose sensitive data from the victim's local filesystem. Specifically, `KerasFileEditor` extracts attributes and datasets from linked files into its internal structures, while `keras.saving.load_weights` loads weights from linked files into the user's model. This issue can be exploited by providing a malicious `.h5`, `.weights.h5`, or `.keras` file containing ExternalLinks.

Properties

severity
MEDIUM
summary
Keras: HDF5 links can disclose local file contents
epss_score
0.00647
cvss_score
6.5
ghsa_published
2026-08-02T06:30:20Z
source_url
https://github.com/advisories/GHSA-m8wh-29wm-52mv
ghsa_updated
2026-08-07T20:35:49Z
ghsa_id
GHSA-m8wh-29wm-52mv
score
6.5
cve_id
CVE-2026-9335
cvss_vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
signal_observed_at
2026-09-11T17:55:57+00:00
is_ghsa_only
false
vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
published_at
2026-08-02T05:16:20.827
last_modified
2026-08-31T19:23:31.967
epss_percentile
0.49235

Related Entities (6)

DESCRIBED_BY (1)

[Source]NVD

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

REPORTED_BY (1)

[Source]GitHub Advisory Database

AFFECTS (1)

[Software]pip/keras

VULNERABLE_TO (1)

[Software]pip/keras

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-9335 (CVSS 6.5) — Ninja Signal Threat Intelligence | Ninja Signal