Skip to content

[GHSA-x3vf-39hj-gxr4] Record 1.87 as the fixed version for biopython - #8949

Open
tonytonycoder11 wants to merge 1 commit into
github:tonytonycoder11/advisory-improvement-8949from
tonytonycoder11:tonytonycoder11-GHSA-x3vf-39hj-gxr4
Open

[GHSA-x3vf-39hj-gxr4] Record 1.87 as the fixed version for biopython#8949
tonytonycoder11 wants to merge 1 commit into
github:tonytonycoder11/advisory-improvement-8949from
tonytonycoder11:tonytonycoder11-GHSA-x3vf-39hj-gxr4

Conversation

@tonytonycoder11

Copy link
Copy Markdown

Summary

The affected range closes with last_affected: 1.86, which leaves the record without a fixed version. Biopython 1.87 contains the fix for CVE-2025-68463, so the range should close with fixed: 1.87.

Evidence

The 1.87 release notes state: "Addressed security issue CVE-2025-68463 in Bio.Entrez.Parser if parsing untrusted files." See NEWS.rst at the 1.87 tag.

Commit 736c96f, already referenced by this advisory, is contained in tag biopython-187 and is not contained in biopython-186.

PyPI lists no release between 1.86 and 1.87, so 1.87 is the first patched version.

Validation

One advisory changed, one range event replaced. The file parses with python -m json.tool. Both source URLs were checked against the upstream repository.

@github-actions
github-actions Bot changed the base branch from main to tonytonycoder11/advisory-improvement-8949 August 2, 2026 20:46
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant