Python 3.10.22
Release date: Oct. 1, 2026
This is the final security release of Python 3.10
Python 3.10 has reached end of life. Python 3.10.22 is its final release, and the 3.10 series will receive no further security updates. Please upgrade to a supported Python version.
Note: The release you're looking at is Python 3.10.22, a security bugfix release for the legacy 3.10 series. Python 3.14 is now the latest feature release series of Python 3. Get the latest release of 3.14.x here.
Security content in this release
- gh-158446: Fix crashes or incorrect output when formatting float or complex values with precision close to INT_MAX.
- CVE-2026-19553 — gh-156793:
ssl.SSLContext.wrap_bio()now validates itsserver_side,server_hostname, andsessionarguments.asyncioalso validates TLSserver_hostnamearguments. On Python 3.10 and 3.11, missing hostnames withcheck_hostnameenabled emitDeprecationWarningfor compatibility; they raiseValueErroron Python 3.13 and later. - CVE-2026-87910 — gh-157265: Apply tarfile extraction filters when a link falls back to extracting an archive member, skipping members rejected by the filter.
- CVE-2026-82049 — gh-157190: Fix a tarfile extraction-filter vulnerability involving hard links to symbolic links that could expose files outside the destination and change their permissions or modification times.
- gh-157953: Update bundled libexpat to version 2.8.5.
- CVE-2026-15310 — gh-156002: Bound
zipfiledecompression per read for bzip2 and LZMA members, preventing unbounded allocations from small compressed members. Third-party decompressors supplied by monkey-patching_get_decompressor()that lackneeds_inputand two-argumentdecompress()remain vulnerable. - CVE-2026-19672 — gh-155999: Prevent tarfile extraction filters from creating directories outside the destination for paths that leave it and then return.
- CVE-2026-19445 — gh-156293: Fix an ssl crash when an SNI callback switches contexts and the original callback context is no longer referenced.
- CVE-2026-17084 — gh-155292: Restrict stringprep and the IDNA codec to Unicode codepoint attributes defined by RFC 3454.
- CVE-2026-15806 — gh-155694: Scope urllib.request HTTPPasswordMgr credentials by URL scheme to prevent HTTPS credentials from being used for matching HTTP URLs.
- gh-149018: Improve protection against XML hash-flooding attacks in
xml.parsers.expatandxml.etree.ElementTreewhen compiled with libexpat 2.8.0 or later.
No installers
Python 3.10.22 is a source-only release. Python 3.10.11 was the last full bugfix release of Python 3.10 with binary installers. With this final security release, the life cycle described in PEP 619 is complete.
And now for something completely different
When two black holes merge, the newly formed black hole is distorted. It settles towards a stationary state by emitting gravitational waves in a process called ringdown. Like a struck bell, it oscillates with a signal that fades away. These oscillations are described by quasinormal modes; their frequencies and decay times depend on the final black hole’s mass and spin. You can watch spacetime doing its final ringing in this NASA simulation.
We started Python 3.10 with a trip inside a Schwarzschild black hole, so it seems only fair to finish with black holes as well :)
This is Python 3.10’s ringdown. One last release before we switch off the release machinery. Five years of features, fixes, stubborn buildbots, and a rather unreasonable number of tarballs. I cannot quite believe I am writing the last one.
Thank you to everyone who contributed patches, reviewed changes, tested releases, reported bugs, or helped us get a release out when the universe seemed determined to prevent it. It has been a privilege to be your release manager for this series.
Python 3.11 still has another year of security fixes ahead of it, so you have not escaped me yet :)
Files
Source release
| Version | Operating system | Description | File size | Sigstore | GPG | SHA-256 checksum | |
|---|---|---|---|---|---|---|---|
| Gzipped source tarball | Source release | 24.8 MB | .sigstore | SIG | 9448b34d16f8e3db |
||
| XZ compressed source tarball | Source release | 19.0 MB | .sigstore | SIG | c61fe9b1a1a7ec2a |
||
