Skip to content

Python 3.10 hits end of life as five releases fix 8 CVEs

Python 3.10.22 is the last 3.10 release: the branch reached end of life on October 1, 2026, as 3.11 to 3.14 shipped fixes for up to eight CVEs.

By Tech AI Wire Team

4 min read

XLinkedIn
Screenshot of the Python Insider post announcing Python 3.10.22, 3.11.17, 3.12.15, 3.13.16 and 3.14.8, with download links for each release.

By the numbers

CVEs fixed across the five releases
8
of them in the tarfile module
3
end of support for Python 3.11
Oct 2027
end of support for Python 3.12
Oct 2028

Python 3.10 reached end of life on October 1, 2026, five years after it shipped. Its final update, Python 3.10.22, arrived alongside 3.11.17, 3.12.15, 3.13.16 and 3.14.8. Together they fix eight security flaws. Anyone still running 3.10 now gets no more fixes, including for security bugs.

The same batch moves Python 3.13 to security fixes only. Python 3.14 is the newest branch in the batch.

What end of life means for 3.10

"End of life" means the Python core team stops maintaining a version. No more releases come out for it, even when a new security hole is found. The release announcement on Python Insider marks the moment plainly: "This is Python 3.10's ringdown. One last release before we switch off the release machinery."

Pablo Galindo Salgado managed the 3.10 and 3.11 release lines, Linux Compatible reports. The farewell recalls that Python 3.10 started "with a trip inside a Schwarzschild black hole," and ends with black holes too. Thomas Wouters and Hugo van Kemenade, the other release managers, also signed the announcement.

Here is where each supported branch now stands, per the release post:

VersionThis releaseStatusSupport ends
3.103.10.22End of lifeOctober 1, 2026
3.113.11.17Security fixes onlyOctober 2027
3.123.12.15Security fixes onlyOctober 2028
3.133.13.16Now security fixes onlyNot stated in this release
3.143.14.8Newest branchNot stated in this release

The post says 3.13.16 "is the last full maintenance release of 3.13; future 3.13 releases will contain security fixes only."

The eight security fixes

A CVE is a public ID number for a known security flaw. The release post lists eight. All of them ship in every release, except CVE-2026-87910, which does not apply to 3.14.

CVEModuleWhat the fix does
CVE-2026-19553sslSSLContext.wrap_bio() now checks its server_side, server_hostname and session arguments
CVE-2026-82049tarfileCloses an extraction-filter hole with hard links to symbolic links that could expose files outside the target folder
CVE-2026-15310zipfileLimits how much bzip2 and LZMA data is unpacked per read, preventing unbounded memory use
CVE-2026-19672tarfileStops extraction filters from creating folders outside the target
CVE-2026-19445sslFixes a crash when an SNI callback switches contexts
CVE-2026-17084stringprep, IDNALimits both to the Unicode character rules in RFC 3454
CVE-2026-15806urllib.requestScopes HTTPPasswordMgr passwords by URL scheme, so HTTPS credentials are not misused
CVE-2026-87910tarfileApplies extraction filters when a link falls back to extracting an archive member

Three of the eight are in tarfile, the standard-library module that unpacks .tar archives. Its extraction filters are the safety checks that stop an archive from writing files outside the folder you unpack it into. All three fixes close gaps in those checks.

Installers and OpenSSL

Only two of the five releases come with ready-made installers. According to the Python Discourse announcement, 3.10.22, 3.11.17 and 3.12.15 ship as source code only, with no Windows or macOS installers. Python 3.13.16 and 3.14.8 include them.

Those two also update the bundled OpenSSL, the library Python uses for encrypted connections, to version 3.5.9. That applies to the Windows, macOS and Android builds, and 3.14.8 also covers iOS.

What this means for developers

Move off Python 3.10 now. Check every place a version is pinned: Docker base images, CI test matrices, pyproject.toml files and server images. From now on, no 3.10 image will get another security fix.

Pick your target with the support dates in mind. Moving to 3.11 buys only one year, until October 2027. Moving to 3.12 buys two. If you are doing the work anyway, 3.13 or 3.14 gives the longest runway.

Patch first if you unpack archives you did not create. Services that accept uploaded .tar or .zip files are exposed to the tarfile and zipfile fixes. Upgrade those first, and keep extraction filters turned on in your own code.

Check urllib if you send passwords with it. The HTTPPasswordMgr fix stops credentials meant for HTTPS from being reused over another scheme. Code that sets basic-auth passwords through urllib.request should move to the patched releases.

Plan for source builds on older branches. On Windows and macOS, the 3.11 and 3.12 fixes arrive without installers. Get them from your Linux distribution, a container image or a tool that builds Python from source.

Sources

  1. Python 3.10.22, 3.11.17, 3.12.15, 3.13.16 and 3.14.8 are now available! - Python Insider
  2. Python 3.10.22, 3.11.17, 3.12.15, 3.13.16, and 3.14.8 Ship as 3.10 Hits End of Life - Linux Compatible
  3. Python 3.10.22, 3.11.17, 3.12.15, 3.13.16 and 3.14.8 release announcement - Python Discourse

Related articles

The daily brief

Three to five stories a day, and what each one means for the people who build software. Free, no spam.