Python 3.10 hits end of life as five releases fix 8 CVEs
Python 3.10.22 is the last 3.10 release: the branch reached end of life on October 1, 2026, as 3.11 to 3.14 shipped fixes for up to eight CVEs.
4 min read

By the numbers
- CVEs fixed across the five releases
- 8
- of them in the tarfile module
- 3
- end of support for Python 3.11
- Oct 2027
- end of support for Python 3.12
- Oct 2028
Python 3.10 reached end of life on October 1, 2026, five years after it shipped. Its final update, Python 3.10.22, arrived alongside 3.11.17, 3.12.15, 3.13.16 and 3.14.8. Together they fix eight security flaws. Anyone still running 3.10 now gets no more fixes, including for security bugs.
The same batch moves Python 3.13 to security fixes only. Python 3.14 is the newest branch in the batch.
What end of life means for 3.10
"End of life" means the Python core team stops maintaining a version. No more releases come out for it, even when a new security hole is found. The release announcement on Python Insider marks the moment plainly: "This is Python 3.10's ringdown. One last release before we switch off the release machinery."
Pablo Galindo Salgado managed the 3.10 and 3.11 release lines, Linux Compatible reports. The farewell recalls that Python 3.10 started "with a trip inside a Schwarzschild black hole," and ends with black holes too. Thomas Wouters and Hugo van Kemenade, the other release managers, also signed the announcement.
Here is where each supported branch now stands, per the release post:
| Version | This release | Status | Support ends |
|---|---|---|---|
| 3.10 | 3.10.22 | End of life | October 1, 2026 |
| 3.11 | 3.11.17 | Security fixes only | October 2027 |
| 3.12 | 3.12.15 | Security fixes only | October 2028 |
| 3.13 | 3.13.16 | Now security fixes only | Not stated in this release |
| 3.14 | 3.14.8 | Newest branch | Not stated in this release |
The post says 3.13.16 "is the last full maintenance release of 3.13; future 3.13 releases will contain security fixes only."
The eight security fixes
A CVE is a public ID number for a known security flaw. The release post lists eight. All of them ship in every release, except CVE-2026-87910, which does not apply to 3.14.
| CVE | Module | What the fix does |
|---|---|---|
| CVE-2026-19553 | ssl | SSLContext.wrap_bio() now checks its server_side, server_hostname and session arguments |
| CVE-2026-82049 | tarfile | Closes an extraction-filter hole with hard links to symbolic links that could expose files outside the target folder |
| CVE-2026-15310 | zipfile | Limits how much bzip2 and LZMA data is unpacked per read, preventing unbounded memory use |
| CVE-2026-19672 | tarfile | Stops extraction filters from creating folders outside the target |
| CVE-2026-19445 | ssl | Fixes a crash when an SNI callback switches contexts |
| CVE-2026-17084 | stringprep, IDNA | Limits both to the Unicode character rules in RFC 3454 |
| CVE-2026-15806 | urllib.request | Scopes HTTPPasswordMgr passwords by URL scheme, so HTTPS credentials are not misused |
| CVE-2026-87910 | tarfile | Applies extraction filters when a link falls back to extracting an archive member |
Three of the eight are in tarfile, the standard-library module that unpacks .tar archives. Its extraction filters are the safety checks that stop an archive from writing files outside the folder you unpack it into. All three fixes close gaps in those checks.
Installers and OpenSSL
Only two of the five releases come with ready-made installers. According to the Python Discourse announcement, 3.10.22, 3.11.17 and 3.12.15 ship as source code only, with no Windows or macOS installers. Python 3.13.16 and 3.14.8 include them.
Those two also update the bundled OpenSSL, the library Python uses for encrypted connections, to version 3.5.9. That applies to the Windows, macOS and Android builds, and 3.14.8 also covers iOS.
What this means for developers
Move off Python 3.10 now. Check every place a version is pinned: Docker base images, CI test matrices, pyproject.toml files and server images. From now on, no 3.10 image will get another security fix.
Pick your target with the support dates in mind. Moving to 3.11 buys only one year, until October 2027. Moving to 3.12 buys two. If you are doing the work anyway, 3.13 or 3.14 gives the longest runway.
Patch first if you unpack archives you did not create. Services that accept uploaded .tar or .zip files are exposed to the tarfile and zipfile fixes. Upgrade those first, and keep extraction filters turned on in your own code.
Check urllib if you send passwords with it. The HTTPPasswordMgr fix stops credentials meant for HTTPS from being reused over another scheme. Code that sets basic-auth passwords through urllib.request should move to the patched releases.
Plan for source builds on older branches. On Windows and macOS, the 3.11 and 3.12 fixes arrive without installers. Get them from your Linux distribution, a container image or a tool that builds Python from source.
Sources
Related articles

SourceHut build log XSS let attackers take over accounts
A crafted build log could run script in a SourceHut user's browser. ansi2html 1.9.4 fixes the bug, CVE-2026-92973, which hit versions 1.7.0 to 1.9.3.

Rejetto HFS CVE-2026-61500 exploited a day after write-up
HFS 3.0.0 to 3.2.0 signs logins with Math.random(), a flaw Anthropic's Mythos found. Attacks began October 3, a day after the write-up. 3.2.1 fixes it.

Python 3.15.0 final slips to October 9 after surprise rc3
Python 3.15.0rc3 shipped on October 2 to fix late lazy-import bugs, pushing the final Python 3.15.0 release back one week to October 9, 2026.
The daily brief
Three to five stories a day, and what each one means for the people who build software. Free, no spam.