Описание
Biopython is vulnerable to doctype XML external entity (XXE) injection through Bio.Entrez
Bio.Entrez in Biopython through 1.86 allows doctype XXE.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2025-68463
- https://github.com/biopython/biopython/issues/5109
- https://github.com/biopython/biopython/commit/736c96f37b190732ecca9da80ad0cb9d4967214d
- https://github.com/biopython/biopython
- https://github.com/biopython/biopython/blob/master/NEWS.rst
- https://pypi.org/project/biopython/1.87
- http://www.openwall.com/lists/oss-security/2026/05/08/16
Пакеты
Наименование
biopython
pip
Затронутые версииВерсия исправления
<= 1.86
Отсутствует
Связанные уязвимости
CVSS3: 4.9
ubuntu
8 месяцев назад
Bio.Entrez in Biopython through 186 allows doctype XXE.
CVSS3: 7.1
redhat
8 месяцев назад
Bio.Entrez in Biopython through 186 allows doctype XXE.
CVSS3: 4.9
debian
8 месяцев назад
Bio.Entrez in Biopython through 186 allows doctype XXE.