Database/AI/ML frameworks & serving
Keras (HDF5 ExternalLink, incomplete fix): Arbitrary HDF5 file read
CVSS 5.5CVE-2026-12480AI/ML frameworks & servingcurated
Impact
Arbitrary HDF5 file read; incomplete fix for CVE-2026-1669
Who can reach it
Customer-supplied model file
What to do
Upgrade past 3.13.2
References
Related entries
- Keras: unvalidated dataset sizes in .keras loading let a poisoned model exhaust node memoryCVE-2026-12570 · Keras (.keras model loading, H5IOStore.__getitem__)Medium
- Feast operator: tenant-supplied feature repo code runs with elevated privileges, reaching cluster adminCVE-2026-18942 · Feast operator in Red Hat OpenShift AI (feature repository processing)Medium
- BentoML (bentoml build, symlink dereferencing in the build context): bentoml build follows symlinks inside the buildCVE-2026-40610 · BentoML (bentoml build, symlink dereferencing in the build context)Medium
- NVIDIA NemoClaw: sensitive information visible in process invocation leads to information disclosureCVE-2026-65088 · NVIDIA NemoClaw (process invocation exposing sensitive information)Medium
- Kubeflow (Pipelines UI): Stored XSS in the pipeline viewCVE-2024-9526 · Kubeflow (Pipelines UI)Medium
- JupyterLab: extension-manager uninstall passes option-like names to pip, allowing file read and internal SSRFCVE-2026-102904 · JupyterLab PyPI Extension Manager (uninstall handler argument injection)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.