Skip to content

Commit 934f09f

Browse files
committed
Announce Python 3.10.22 and 3.11.17
1 parent 2282657 commit 934f09f

1 file changed

Lines changed: 66 additions & 0 deletions

File tree

  • content/posts/python-31022-31117
Lines changed: 66 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,66 @@
1+
---
2+
title: 'Python 3.10.22 and 3.11.17 are now available!'
3+
publishDate: '2026-10-01'
4+
author: Pablo Galindo
5+
description: 'New source-only security releases for Python 3.10 and 3.11, and a farewell to Python 3.10 as it reaches end of life.'
6+
tags:
7+
- releases
8+
published: true
9+
---
10+
11+
One last lap around the Sun for Python 3.10, and another security update for Python 3.11. **Python 3.10.22 and Python 3.11.17 are now available!**
12+
13+
Get them here:
14+
15+
- [Python 3.10.22](https://www.python.org/downloads/release/python-31022/)
16+
- [Python 3.11.17](https://www.python.org/downloads/release/python-31117/)
17+
18+
**Python 3.10.22 is the final release of Python 3.10.** After five years, the series has reached end of life and will receive no further security updates. If you are still using Python 3.10, please plan your upgrade to a supported version.
19+
20+
Python 3.11 remains in security-fix-only mode until October 2027, as described in [PEP 664](https://peps.python.org/pep-0664/). Security releases are made as needed, with no fixed cadence.
21+
22+
Both releases are **source-only**. There are no Windows or macOS installers: 3.10.11 and 3.11.9 were the last releases in their respective series to include binary installers. These releases contain security fixes rather than new features.
23+
24+
[Discuss this release announcement](https://discuss.python.org/t/python-3-10-22-and-3-11-17-are-now-available/109296).
25+
26+
## Security content in both releases
27+
28+
* [gh-158446](https://github.com/python/cpython/issues/158446): Fix crashes or incorrect output when formatting float or complex values with precision close to `INT_MAX`.
29+
* [CVE-2026-19553](https://www.cve.org/CVERecord?id=CVE-2026-19553) — [gh-156793](https://github.com/python/cpython/issues/156793): `ssl.SSLContext.wrap_bio()` now validates its `server_side`, `server_hostname`, and `session` arguments. `asyncio` also validates TLS `server_hostname` arguments. On Python 3.10 and 3.11, missing hostnames with `check_hostname` enabled emit `DeprecationWarning` for compatibility; they raise `ValueError` on Python 3.13 and later.
30+
* [CVE-2026-87910](https://www.cve.org/CVERecord?id=CVE-2026-87910) — [gh-157265](https://github.com/python/cpython/issues/157265): Apply tarfile extraction filters when a link falls back to extracting an archive member, skipping members rejected by the filter.
31+
* [CVE-2026-82049](https://www.cve.org/CVERecord?id=CVE-2026-82049) — [gh-157190](https://github.com/python/cpython/issues/157190): Fix a tarfile extraction-filter vulnerability involving hard links to symbolic links that could expose files outside the destination and change their permissions or modification times.
32+
* [gh-157953](https://github.com/python/cpython/issues/157953): Update bundled libexpat to version 2.8.5.
33+
* [CVE-2026-15310](https://www.cve.org/CVERecord?id=CVE-2026-15310) — [gh-156002](https://github.com/python/cpython/issues/156002): Bound `zipfile` decompression per read for bzip2 and LZMA members, preventing unbounded allocations from small compressed members. Third-party decompressors supplied by monkey-patching `_get_decompressor()` that lack `needs_input` and two-argument `decompress()` remain vulnerable.
34+
* [CVE-2026-19672](https://www.cve.org/CVERecord?id=CVE-2026-19672) — [gh-155999](https://github.com/python/cpython/issues/155999): Prevent tarfile extraction filters from creating directories outside the destination for paths that leave it and then return.
35+
* [CVE-2026-19445](https://www.cve.org/CVERecord?id=CVE-2026-19445) — [gh-156293](https://github.com/python/cpython/issues/156293): Fix an ssl crash when an SNI callback switches contexts and the original callback context is no longer referenced.
36+
* [CVE-2026-17084](https://www.cve.org/CVERecord?id=CVE-2026-17084) — [gh-155292](https://github.com/python/cpython/issues/155292): Restrict stringprep and the IDNA codec to Unicode codepoint attributes defined by RFC 3454.
37+
* [CVE-2026-15806](https://www.cve.org/CVERecord?id=CVE-2026-15806) — [gh-155694](https://github.com/python/cpython/issues/155694): Scope urllib.request HTTPPasswordMgr credentials by URL scheme to prevent HTTPS credentials from being used for matching HTTP URLs.
38+
39+
## Additional security fix in Python 3.10.22
40+
41+
* [gh-149018](https://github.com/python/cpython/issues/149018): Improve protection against XML hash-flooding attacks in `xml.parsers.expat` and `xml.etree.ElementTree` when compiled with libexpat 2.8.0 or later.
42+
43+
This XML hash-flooding protection was already included in Python 3.11.16.
44+
45+
For the full details, see the [3.10.22 changelog](https://docs.python.org/release/3.10.22/whatsnew/changelog.html) and [3.11.17 changelog](https://docs.python.org/release/3.11.17/whatsnew/changelog.html).
46+
47+
## And now for something completely different
48+
49+
When two black holes merge, the newly formed black hole is distorted. It settles towards a stationary state by emitting gravitational waves in a process called **ringdown**. Like a struck bell, it oscillates with a signal that fades away. These oscillations are described by quasinormal modes; their frequencies and decay times depend on the final black hole’s mass and spin. You can watch spacetime doing its final ringing in [this NASA simulation](https://svs.gsfc.nasa.gov/13197).
50+
51+
We started Python 3.10 with [a trip inside a Schwarzschild black hole](https://blog.python.org/2021/10/python-3100-is-available/), so it seems only fair to finish with black holes as well :)
52+
53+
This is Python 3.10’s ringdown. One last release before we switch off the release machinery. Five years of features, fixes, stubborn buildbots, and a rather unreasonable number of tarballs. I cannot quite believe I am writing the last one.
54+
55+
Thank you, Ned and Steve, and everyone who contributed patches, reviewed changes, tested releases, reported bugs, or helped us get a release out when the universe seemed determined to prevent it. It has been a privilege to be your release manager for this series.
56+
57+
Python 3.11 still has another year of security fixes ahead of it, so you have not escaped me yet :)
58+
59+
## We hope you enjoy the new releases!
60+
61+
Thank you to all the volunteers who made these releases possible. Please consider supporting Python by contributing your time or through the [Python Software Foundation](https://www.python.org/psf-landing/).
62+
63+
Your friendly release team,
64+
[Ned Deily](https://discuss.python.org/u/nad)
65+
[Steve Dower](https://discuss.python.org/u/steve.dower)
66+
[Pablo Galindo Salgado](https://discuss.python.org/u/pablogsal)

0 commit comments

Comments
 (0)