Notice: This page displays a fallback because interactive scripts did not run. Possible causes include disabled JavaScript or failure to load scripts or stylesheets.

Python 3.11.17

Release date: Oct. 1, 2026

This is a security release of Python 3.11

Note: The release you're looking at is Python 3.11.17, a security bugfix release for the legacy 3.11 series. Python 3.14 is now the latest feature release series of Python 3. Get the latest release of 3.14.x here.

Security content in this release

  • gh-158446: Fix crashes or incorrect output when formatting float or complex values with precision close to INT_MAX.
  • CVE-2026-19553 — gh-156793: ssl.SSLContext.wrap_bio() now validates its server_side, server_hostname, and session arguments. asyncio also validates TLS server_hostname arguments. On Python 3.10 and 3.11, missing hostnames with check_hostname enabled emit DeprecationWarning for compatibility; they raise ValueError on Python 3.13 and later.
  • CVE-2026-87910 — gh-157265: Apply tarfile extraction filters when a link falls back to extracting an archive member, skipping members rejected by the filter.
  • CVE-2026-82049 — gh-157190: Fix a tarfile extraction-filter vulnerability involving hard links to symbolic links that could expose files outside the destination and change their permissions or modification times.
  • gh-157953: Update bundled libexpat to version 2.8.5.
  • CVE-2026-15310 — gh-156002: Bound zipfile decompression per read for bzip2 and LZMA members, preventing unbounded allocations from small compressed members. Third-party decompressors supplied by monkey-patching _get_decompressor() that lack needs_input and two-argument decompress() remain vulnerable.
  • CVE-2026-19672 — gh-155999: Prevent tarfile extraction filters from creating directories outside the destination for paths that leave it and then return.
  • CVE-2026-19445 — gh-156293: Fix an ssl crash when an SNI callback switches contexts and the original callback context is no longer referenced.
  • CVE-2026-17084 — gh-155292: Restrict stringprep and the IDNA codec to Unicode codepoint attributes defined by RFC 3454.
  • CVE-2026-15806 — gh-155694: Scope urllib.request HTTPPasswordMgr credentials by URL scheme to prevent HTTPS credentials from being used for matching HTTP URLs.

No installers

According to the release calendar specified in PEP 664, Python 3.11 is in the "security fixes only" stage of its life cycle: the 3.11 branch only accepts security fixes, and releases of those are made irregularly in source-only form until October 2027. Python 3.11 isn't receiving regular bug fixes anymore, and binary installers are no longer provided for it. Python 3.11.9 was the last full bugfix release of Python 3.11 with binary installers.

Full Changelog

Files

Version Operating system Description File size Sigstore GPG SHA-256 checksum
Gzipped source tarball Source release 25.4 MB .sigstore SIG 53cdee63ac4bf12387b7b33a53d3b1f8f4941cad73807a7b4fe91bb001ef004a
XZ compressed source tarball Source release 19.4 MB .sigstore SIG bfb74ad39efae27cda510f134ab408e00f9992c56851cfc0b1cdb5646da11599