What is CVE-2026-9335?
A vulnerability in Keras (≤3.14.0) allows arbitrary local HDF5 file content disclosure via `KerasFileEditor` and `keras.saving.load_weights` functions due to improper handling of HDF5 ExternalLinks. Affected users should update the library or avoid loading model files from untrusted sources.
Azərbaycanca: Keras kitabxanasında (≤3.14.0) HDF5 ExternalLink-lərin düzgün idarə olunmaması səbəbindən `KerasFileEditor` və `keras.saving.load_weights` funksiyaları vasitəsilə ixtiyari lokal HDF5 faylının məzmununun ifşa edilməsinə imkan verən zəiflik aşkarlanıb. Təsirə məruz qalan istifadəçilər kitabxananı yeniləməli və ya etibarsız mənbələrdən model fayllarını yükləməkdən çəkinməlidir.
FAQ2
Which functions can be exploited for the CVE-2026-9335 vulnerability in the Keras library?
The vulnerability can be exploited through the `KerasFileEditor` and `keras.saving.load_weights` functions.
What security measures are recommended for users affected by CVE-2026-9335?
Affected users should update the Keras library or avoid loading model files from untrusted sources.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.