|
| 1 | +--- |
| 2 | +title: 'Python 3.10.22 and 3.11.17 are now available!' |
| 3 | +publishDate: '2026-10-01' |
| 4 | +author: Pablo Galindo |
| 5 | +description: 'New source-only security releases for Python 3.10 and 3.11, and a farewell to Python 3.10 as it reaches end of life.' |
| 6 | +tags: |
| 7 | + - releases |
| 8 | +published: true |
| 9 | +--- |
| 10 | + |
| 11 | +One last lap around the Sun for Python 3.10, and another security update for Python 3.11. **Python 3.10.22 and Python 3.11.17 are now available!** |
| 12 | + |
| 13 | +Get them here: |
| 14 | + |
| 15 | +- [Python 3.10.22](https://www.python.org/downloads/release/python-31022/) |
| 16 | +- [Python 3.11.17](https://www.python.org/downloads/release/python-31117/) |
| 17 | + |
| 18 | +**Python 3.10.22 is the final release of Python 3.10.** After five years, the series has reached end of life and will receive no further security updates. If you are still using Python 3.10, please plan your upgrade to a supported version. |
| 19 | + |
| 20 | +Python 3.11 remains in security-fix-only mode until October 2027, as described in [PEP 664](https://peps.python.org/pep-0664/). Security releases are made as needed, with no fixed cadence. |
| 21 | + |
| 22 | +Both releases are **source-only**. There are no Windows or macOS installers: 3.10.11 and 3.11.9 were the last releases in their respective series to include binary installers. These releases contain security fixes rather than new features. |
| 23 | + |
| 24 | +[Discuss this release announcement](https://discuss.python.org/t/python-3-10-22-and-3-11-17-are-now-available/109296). |
| 25 | + |
| 26 | +## Security content in both releases |
| 27 | + |
| 28 | +* [gh-158446](https://github.com/python/cpython/issues/158446): Fix crashes or incorrect output when formatting float or complex values with precision close to `INT_MAX`. |
| 29 | +* [CVE-2026-19553](https://www.cve.org/CVERecord?id=CVE-2026-19553) — [gh-156793](https://github.com/python/cpython/issues/156793): `ssl.SSLContext.wrap_bio()` now validates its `server_side`, `server_hostname`, and `session` arguments. `asyncio` also validates TLS `server_hostname` arguments. On Python 3.10 and 3.11, missing hostnames with `check_hostname` enabled emit `DeprecationWarning` for compatibility; they raise `ValueError` on Python 3.13 and later. |
| 30 | +* [CVE-2026-87910](https://www.cve.org/CVERecord?id=CVE-2026-87910) — [gh-157265](https://github.com/python/cpython/issues/157265): Apply tarfile extraction filters when a link falls back to extracting an archive member, skipping members rejected by the filter. |
| 31 | +* [CVE-2026-82049](https://www.cve.org/CVERecord?id=CVE-2026-82049) — [gh-157190](https://github.com/python/cpython/issues/157190): Fix a tarfile extraction-filter vulnerability involving hard links to symbolic links that could expose files outside the destination and change their permissions or modification times. |
| 32 | +* [gh-157953](https://github.com/python/cpython/issues/157953): Update bundled libexpat to version 2.8.5. |
| 33 | +* [CVE-2026-15310](https://www.cve.org/CVERecord?id=CVE-2026-15310) — [gh-156002](https://github.com/python/cpython/issues/156002): Bound `zipfile` decompression per read for bzip2 and LZMA members, preventing unbounded allocations from small compressed members. Third-party decompressors supplied by monkey-patching `_get_decompressor()` that lack `needs_input` and two-argument `decompress()` remain vulnerable. |
| 34 | +* [CVE-2026-19672](https://www.cve.org/CVERecord?id=CVE-2026-19672) — [gh-155999](https://github.com/python/cpython/issues/155999): Prevent tarfile extraction filters from creating directories outside the destination for paths that leave it and then return. |
| 35 | +* [CVE-2026-19445](https://www.cve.org/CVERecord?id=CVE-2026-19445) — [gh-156293](https://github.com/python/cpython/issues/156293): Fix an ssl crash when an SNI callback switches contexts and the original callback context is no longer referenced. |
| 36 | +* [CVE-2026-17084](https://www.cve.org/CVERecord?id=CVE-2026-17084) — [gh-155292](https://github.com/python/cpython/issues/155292): Restrict stringprep and the IDNA codec to Unicode codepoint attributes defined by RFC 3454. |
| 37 | +* [CVE-2026-15806](https://www.cve.org/CVERecord?id=CVE-2026-15806) — [gh-155694](https://github.com/python/cpython/issues/155694): Scope urllib.request HTTPPasswordMgr credentials by URL scheme to prevent HTTPS credentials from being used for matching HTTP URLs. |
| 38 | + |
| 39 | +## Additional security fix in Python 3.10.22 |
| 40 | + |
| 41 | +* [gh-149018](https://github.com/python/cpython/issues/149018): Improve protection against XML hash-flooding attacks in `xml.parsers.expat` and `xml.etree.ElementTree` when compiled with libexpat 2.8.0 or later. |
| 42 | + |
| 43 | +This XML hash-flooding protection was already included in Python 3.11.16. |
| 44 | + |
| 45 | +For the full details, see the [3.10.22 changelog](https://docs.python.org/release/3.10.22/whatsnew/changelog.html) and [3.11.17 changelog](https://docs.python.org/release/3.11.17/whatsnew/changelog.html). |
| 46 | + |
| 47 | +## And now for something completely different |
| 48 | + |
| 49 | +When two black holes merge, the newly formed black hole is distorted. It settles towards a stationary state by emitting gravitational waves in a process called **ringdown**. Like a struck bell, it oscillates with a signal that fades away. These oscillations are described by quasinormal modes; their frequencies and decay times depend on the final black hole’s mass and spin. You can watch spacetime doing its final ringing in [this NASA simulation](https://svs.gsfc.nasa.gov/13197). |
| 50 | + |
| 51 | +We started Python 3.10 with [a trip inside a Schwarzschild black hole](https://blog.python.org/2021/10/python-3100-is-available/), so it seems only fair to finish with black holes as well :) |
| 52 | + |
| 53 | +This is Python 3.10’s ringdown. One last release before we switch off the release machinery. Five years of features, fixes, stubborn buildbots, and a rather unreasonable number of tarballs. I cannot quite believe I am writing the last one. |
| 54 | + |
| 55 | +Thank you, Ned and Steve, and everyone who contributed patches, reviewed changes, tested releases, reported bugs, or helped us get a release out when the universe seemed determined to prevent it. It has been a privilege to be your release manager for this series. |
| 56 | + |
| 57 | +Python 3.11 still has another year of security fixes ahead of it, so you have not escaped me yet :) |
| 58 | + |
| 59 | +## We hope you enjoy the new releases! |
| 60 | + |
| 61 | +Thank you to all the volunteers who made these releases possible. Please consider supporting Python by contributing your time or through the [Python Software Foundation](https://www.python.org/psf-landing/). |
| 62 | + |
| 63 | +Your friendly release team, |
| 64 | +[Ned Deily](https://discuss.python.org/u/nad) |
| 65 | +[Steve Dower](https://discuss.python.org/u/steve.dower) |
| 66 | +[Pablo Galindo Salgado](https://discuss.python.org/u/pablogsal) |
0 commit comments