GPU VulnDB

Database/AI/ML frameworks & serving

Keras (HDF5 external links): Arbitrary local file read during model load

CVE-2026-1669AI/ML frameworks & servingcurated

Impact

Arbitrary local file read during model load

Who can reach it

Customer-supplied HDF5 model — reads provider or co-tenant files visible to the process

What to do

Upgrade; better, disallow HDF5. Note the process' service-account tokens and mounted secrets are in scope

References

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.