← Vulnerability feed

Vulnerability record · CVE-2026-1462 · published 13 April 2026

CVE-2026-1462: Keras deserialization of untrusted data vulnerability

Keras · Keras

A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses the security guarantees of `safe_mode` and enables arbitrary attacker-controlled code execution during model inference under the victim's privileges. The issue arises due to the unconditional loading of external SavedModels, serialization of attacker-controlled file paths, and the lack of validation in the `from_config()` method.

7.8 CVSS 3.1 High EPSS 0.40% · top 67.9% CWE-502 · Deserialization of untrusted data
7.8CVSS 3.1 base score
0.40%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
7References, 1 tagged exploit
15 Jul 2026Last modified by NVD

Description

A vulnerability in the `TFSMLayer` class of the `keras` package, version 3.13.0, allows attacker-controlled TensorFlow SavedModels to be loaded during deserialization of `.keras` models, even when `safe_mode=True`. This bypasses the security guarantees of `safe_mode` and enables arbitrary attacker-controlled code execution during model inference under the victim's privileges. The issue arises due to the unconditional loading of external SavedModels, serialization of attacker-controlled file paths, and the lack of validation in the `from_config()` method.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2026-1462 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.7CVE-2026-42271LiteLLM MCP test endpoints allow authenticated OS command injectionLiteLLM versions 1.74.2 through before 1.83.7 expose two MCP preview endpoints (POST /mcp-rest/test/connection and POST /mcp-rest/test/tools/list) th…KEVEPSS 13%analysed6.5CVE-2026-48710Starlette Host header validation flaw enables request.url path mismatchStarlette before 1.0.1 did not validate the HTTP Host header before using it to rebuild request.url, so a malformed Host value could make request.url…KEVEPSS 7.1%analysed9.9CVE-2026-5483Redhat openshift ai vulnerabilityA flaw was found in odh-dashboard in Red Hat Openshift AI. This vulnerability in the `odh-dashboard` component of Red Hat OpenShift AI (RHOAI) allows…EPSS 0.65%9.8CVE-2026-12481Keras deserialization of untrusted data vulnerabilityA vulnerability in keras-team/keras version 3.14.0 allows for arbitrary code execution due to improper handling of deserialization in the `Lambda` la…EPSS 0.72%9.8CVE-2024-3660Keras code injection vulnerabilityA arbitrary code injection vulnerability in TensorFlow's Keras framework (<2.13) allows attackers to execute arbitrary code with the same permissions…EPSS 1.7%8.8CVE-2024-7557Redhat openshift ai vulnerabilityA vulnerability was found in OpenShift AI that allows for authentication bypass and privilege escalation across models within the same namespace. Whe…EPSS 0.93%8.7CVE-2023-54365Traefik uncontrolled resource consumption vulnerabilityTraefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of-service vulnerability in HTTP/2 request handling inherited from the Go standard libr…EPSS 0.77%8.6CVE-2025-9906Keras deserialization of untrusted data vulnerabilityThe Keras Model.load_model method can be exploited to achieve arbitrary code execution, even with safe_mode=True. One can create a specially crafted …EPSS 0.20%

Source: NIST National Vulnerability Database (record CVE-2026-1462), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.