Vulnerability Database

318,251

Total vulnerabilities in the database

CVE-2026-0897

Allocation of Resources Without Limits or Throttling in the HDF5 weight loading component in Google Keras 3.0.0 through 3.13.0 on all platforms allows a remote attacker to cause a Denial of Service (DoS) through memory exhaustion and a crash of the Python interpreter via a crafted .keras archive containing a valid model.weights.h5 file whose dataset declares an extremely large shape.

  • Published: Jan 15, 2026
  • Updated: Jan 16, 2026
  • CVE: CVE-2026-0897
  • Exploit:

No technical information available.

CWEs: