Python 3.10 Ends Life, 3.14.8 Leads Coordinated Security Update Across Five Versions
Python released synchronized updates for five versions (3.10.22, 3.11.17, 3.12.15, 3.13.16, 3.14.8) with shared security fixes for tar, ZIP, HTTPS, and TLS vulnerabilities, while marking Python 3.10 end-of-life after five years and urging immediate upgrades.
Python Releases Coordinated Security Updates Across Five Versions
On September 30, Python.org released Python 3.14.8, followed by 3.10.22, 3.11.17, 3.12.15, and 3.13.16 on October 1. This synchronized update delivers security patches to all currently supported Python series.
Version-Specific Details
Python 3.10.22 : Final release for the 3.10 series, completing PEP 619. Only source code provided; no Windows or macOS installers. Last binary release was April 2023.
Python 3.11.17 : Continues security-fix-only mode since April 2024; security patches until October 2027.
Python 3.12.15 : Still in active maintenance with security updates until October 2028; source-only release.
Python 3.13.16 : Last full maintenance release for 3.13; future releases will be security-only. Provides binary installers for Windows, macOS, and Android.
Python 3.14.8 : Current feature series, eighth maintenance release, designated as an expedited security update. Includes ~354 bug fixes, build improvements, and documentation changes from 142 contributors since 3.14.7. Binary installers for Windows, macOS, Android, and iOS; includes latest cryptographic protocol stack.
Why Python 3.10 End-of-Life Matters
Python 3.10, released October 4, 2021, reaches end-of-life after its five-year lifecycle. After October 2026, any vulnerabilities discovered in 3.10 will never be patched. For individual developers this is a gentle upgrade reminder; for enterprises running legacy systems on 3.10, it becomes a compliance issue often triggering migration projects. The 3.10 series introduced union types (X | Y), structural pattern matching (match/case), explicit type aliases, and optional length checking in zip(). Release manager Pablo Galindo Salgado oversaw 3.10 and 3.11; his notes read more like a farewell letter than a changelog.
Security Fixes Common to All Five Releases
All five versions share a core set of security fixes addressing several attack vectors:
CVE-2026-82049 : Crafted tar archives with hard links to symbolic links could access files outside the extraction directory.
CVE-2026-19672 : Path traversal via "dot-dot" sequences (e.g., ../evil/../dest/sub/file) bypassing containment checks.
CVE-2026-15310 : ZIP decompression bomb vulnerability; limits data decompressed in a single read operation to prevent small bzip2 or LZMA members from expanding into memory-exhausting "monsters".
CVE-2026-15806 : HTTPS credential reuse flaw allowing HTTPPasswordMgr to reuse credentials over plain HTTP.
CVE-2026-19553 : TLS fix making ssl.SSLContext.wrap_bio() validate hostnames the same way as wrap_socket(). In Python 3.13+, missing hostname now raises ValueError instead of a warning.
Additional updates: libexpat upgraded to 2.8.5; Python 3.10.22 adds XML hash flooding hardening; Python 3.13.16 and 3.14.8 upgrade OpenSSL to 3.5.9. Note that source-only releases 3.10–3.12 do not bundle OpenSSL, so only the newer two versions include the OpenSSL update.
Upgrade Guidance
The release team advises immediate upgrade for anyone still on Python 3.10. Teams planning upgrade timing should note that 3.12 and 3.13 offer longer security windows, while 3.14 is the newest but moves fastest. Salgado indicates he will likely remain release manager through 3.11's end-of-life in October 2027.
A Black Hole Bookends Python 3.10's Lifecycle
Following a tradition of ending release notes with a scientific curiosity, Python 3.10's launch article described falling into a Schwarzschild black hole. Five years later, the final release closes with "ringdown"—the gravitational wave chirp emitted as merging black holes settle. As Salgado wrote, "We started Python 3.10's development with a journey into a Schwarzschild black hole, so ending with a black hole seems fitting."
Signed-in readers can open the original source through BestHub's protected redirect.
This article has been distilled and summarized from source material, then republished for learning and reference. If you believe it infringes your rights, please contactand we will review it promptly.
21CTO
21CTO (21CTO.com) offers developers community, training, and services, making it your go‑to learning and service platform.
How this landed with the community
Was this worth your time?
0 Comments
Thoughtful readers leave field notes, pushback, and hard-won operational detail here.
