Database/AI/ML frameworks & serving
Keras: Deserialization of untrusted data in 3.11.0–3.11.2
CVSS 9.8CVE-2025-49655AI/ML frameworks & servingcurated
Impact
Deserialization of untrusted data in 3.11.0–3.11.2 → malicious model runs arbitrary code
Who can reach it
Customer-supplied model file
What to do
Upgrade to 3.11.3+
References
Related entries
- Keras: Safe-mode bypass in Keras 3.0.0–3.10.0CVE-2025-8747 · KerasHigh
- Keras: Code execution from crafted `.keras` archive despite safe modeCVE-2025-9906 · KerasHigh
- Ollama (API auth): Critical authentication bypass on API endpoints through v0.12.3CVE-2025-63389 · Ollama (API auth)Critical
- Portkey AI Gateway: Gateway resolves the destination baseURL from attacker-controlled precedenceCVE-2025-66405 · Portkey AI GatewayCritical
- MLflow (jobs API): `/ajax-api/3.0/jobs/*` unauthenticated even with basic-auth enabledCVE-2026-0545 · MLflow (jobs API)Critical
- Keras (Lambda layer): Arbitrary code execution via Lambda-layer deserialization in 3.14.0CVE-2026-12481 · Keras (Lambda layer)Critical
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.