Notice: This page displays a fallback because interactive scripts did not run. Possible causes include disabled JavaScript or failure to load scripts or stylesheets.

Python 3.10.22

Warning: Python 3.10.22 reached end-of-life on 2026-10-01. It is no longer supported and does not receive security updates. We recommend upgrading to the latest Python release.

Release date: Oct. 1, 2026

This is the final security release of Python 3.10

Python 3.10 has reached end of life. Python 3.10.22 is its final release, and the 3.10 series will receive no further security updates. Please upgrade to a supported Python version.

Note: The release you're looking at is Python 3.10.22, a security bugfix release for the legacy 3.10 series. Python 3.14 is now the latest feature release series of Python 3. Get the latest release of 3.14.x here.

Security content in this release

  • gh-158446: Fix crashes or incorrect output when formatting float or complex values with precision close to INT_MAX.
  • CVE-2026-19553 — gh-156793: ssl.SSLContext.wrap_bio() now validates its server_side, server_hostname, and session arguments. asyncio also validates TLS server_hostname arguments. On Python 3.10 and 3.11, missing hostnames with check_hostname enabled emit DeprecationWarning for compatibility; they raise ValueError on Python 3.13 and later.
  • CVE-2026-87910 — gh-157265: Apply tarfile extraction filters when a link falls back to extracting an archive member, skipping members rejected by the filter.
  • CVE-2026-82049 — gh-157190: Fix a tarfile extraction-filter vulnerability involving hard links to symbolic links that could expose files outside the destination and change their permissions or modification times.
  • gh-157953: Update bundled libexpat to version 2.8.5.
  • CVE-2026-15310 — gh-156002: Bound zipfile decompression per read for bzip2 and LZMA members, preventing unbounded allocations from small compressed members. Third-party decompressors supplied by monkey-patching _get_decompressor() that lack needs_input and two-argument decompress() remain vulnerable.
  • CVE-2026-19672 — gh-155999: Prevent tarfile extraction filters from creating directories outside the destination for paths that leave it and then return.
  • CVE-2026-19445 — gh-156293: Fix an ssl crash when an SNI callback switches contexts and the original callback context is no longer referenced.
  • CVE-2026-17084 — gh-155292: Restrict stringprep and the IDNA codec to Unicode codepoint attributes defined by RFC 3454.
  • CVE-2026-15806 — gh-155694: Scope urllib.request HTTPPasswordMgr credentials by URL scheme to prevent HTTPS credentials from being used for matching HTTP URLs.
  • gh-149018: Improve protection against XML hash-flooding attacks in xml.parsers.expat and xml.etree.ElementTree when compiled with libexpat 2.8.0 or later.

No installers

Python 3.10.22 is a source-only release. Python 3.10.11 was the last full bugfix release of Python 3.10 with binary installers. With this final security release, the life cycle described in PEP 619 is complete.

And now for something completely different

When two black holes merge, the newly formed black hole is distorted. It settles towards a stationary state by emitting gravitational waves in a process called ringdown. Like a struck bell, it oscillates with a signal that fades away. These oscillations are described by quasinormal modes; their frequencies and decay times depend on the final black hole’s mass and spin. You can watch spacetime doing its final ringing in this NASA simulation.

We started Python 3.10 with a trip inside a Schwarzschild black hole, so it seems only fair to finish with black holes as well :)

This is Python 3.10’s ringdown. One last release before we switch off the release machinery. Five years of features, fixes, stubborn buildbots, and a rather unreasonable number of tarballs. I cannot quite believe I am writing the last one.

Thank you to everyone who contributed patches, reviewed changes, tested releases, reported bugs, or helped us get a release out when the universe seemed determined to prevent it. It has been a privilege to be your release manager for this series.

Python 3.11 still has another year of security fixes ahead of it, so you have not escaped me yet :)

Full Changelog

Files

Version Operating system Description File size Sigstore GPG SHA-256 checksum
Gzipped source tarball Source release 24.8 MB .sigstore SIG 9448b34d16f8e3db0964ac3ed9fb283197747543c2c021f283ffd2c8b7287357
XZ compressed source tarball Source release 19.0 MB .sigstore SIG c61fe9b1a1a7ec2a0b0388e664187c378a5325a89e3606d220abf5bdfccb2543