{
  "@context": "https://openvex.dev/ns/v0.2.0",
  "@id": "https://data.datagrok.ai/vex/jkg_python/bleeding-edge.json",
  "author": "Datagrok",
  "timestamp": "2026-08-24T01:06:28Z",
  "version": 1,
  "statements": [
    {
      "vulnerability": {
        "name": "CVE-2024-55459"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:cb8e9d7f14c93054763c53b08ecbec4542d3b323141579667df13867e2a4f758?tag=bleeding-edge"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "keras 2.15 is the last Keras-2 release; every fix for this advisory is Keras-3-only, and the kernel keeps Keras 2 while efficientnet and tf.keras (Keras-2 API) user scripts depend on it. Exploitation requires the kernel to load an attacker-supplied model/config file — in this image the only actor able to do that is the script author, who already executes arbitrary code in the same kernel process by design (server-side scripting), so no privilege boundary is crossed."
    },
    {
      "vulnerability": {
        "name": "CVE-2025-12058"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:cb8e9d7f14c93054763c53b08ecbec4542d3b323141579667df13867e2a4f758?tag=bleeding-edge"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2025-12060"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:cb8e9d7f14c93054763c53b08ecbec4542d3b323141579667df13867e2a4f758?tag=bleeding-edge"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2025-3000"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:cb8e9d7f14c93054763c53b08ecbec4542d3b323141579667df13867e2a4f758?tag=bleeding-edge"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2025-9906"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:cb8e9d7f14c93054763c53b08ecbec4542d3b323141579667df13867e2a4f758?tag=bleeding-edge"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-0994"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:cb8e9d7f14c93054763c53b08ecbec4542d3b323141579667df13867e2a4f758?tag=bleeding-edge"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "python-protobuf is capped <5 by tensorflow 2.15 (kept for the Keras-2 API). The parse-time resource exhaustion can only be triggered by input the script author feeds their own kernel process, which they can already terminate directly; no other principal parses protobuf here."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-11816"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:cb8e9d7f14c93054763c53b08ecbec4542d3b323141579667df13867e2a4f758?tag=bleeding-edge"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-12479"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:cb8e9d7f14c93054763c53b08ecbec4542d3b323141579667df13867e2a4f758?tag=bleeding-edge"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-12480"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:cb8e9d7f14c93054763c53b08ecbec4542d3b323141579667df13867e2a4f758?tag=bleeding-edge"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-12481"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:cb8e9d7f14c93054763c53b08ecbec4542d3b323141579667df13867e2a4f758?tag=bleeding-edge"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-12482"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:cb8e9d7f14c93054763c53b08ecbec4542d3b323141579667df13867e2a4f758?tag=bleeding-edge"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-12484"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:cb8e9d7f14c93054763c53b08ecbec4542d3b323141579667df13867e2a4f758?tag=bleeding-edge"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-1462"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:cb8e9d7f14c93054763c53b08ecbec4542d3b323141579667df13867e2a4f758?tag=bleeding-edge"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-54284"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:cb8e9d7f14c93054763c53b08ecbec4542d3b323141579667df13867e2a4f758?tag=bleeding-edge"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-59893"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:cb8e9d7f14c93054763c53b08ecbec4542d3b323141579667df13867e2a4f758?tag=bleeding-edge"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-59894"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:cb8e9d7f14c93054763c53b08ecbec4542d3b323141579667df13867e2a4f758?tag=bleeding-edge"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-69247"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:cb8e9d7f14c93054763c53b08ecbec4542d3b323141579667df13867e2a4f758?tag=bleeding-edge"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-69248"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:cb8e9d7f14c93054763c53b08ecbec4542d3b323141579667df13867e2a4f758?tag=bleeding-edge"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-69249"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:cb8e9d7f14c93054763c53b08ecbec4542d3b323141579667df13867e2a4f758?tag=bleeding-edge"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-71491"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:cb8e9d7f14c93054763c53b08ecbec4542d3b323141579667df13867e2a4f758?tag=bleeding-edge"
        }
      ],
      "status": "affected",
      "action_statement": "A fix is available in a newer package version; upgrade the affected package."
    },
    {
      "vulnerability": {
        "name": "CVE-2026-9335"
      },
      "products": [
        {
          "@id": "pkg:oci/jkg_python@sha256:cb8e9d7f14c93054763c53b08ecbec4542d3b323141579667df13867e2a4f758?tag=bleeding-edge"
        }
      ],
      "status": "not_affected",
      "justification": "vulnerable_code_cannot_be_controlled_by_adversary",
      "impact_statement": "Keras-3-only fix; Keras 2 kept for efficientnet / tf.keras user scripts. Requires loading an attacker-supplied model into a kernel whose script author already executes arbitrary code by design — same rationale as CVE-2024-55459."
    }
  ]
}
