Python 2.x — End of Life
EOL Critical riskPython 2.x reached end of life on Jan 1, 2020, 2471 days ago, and no longer receives security fixes. The most recent release in this series is 2.7.18. 15 CVEs are tracked for this series, including 2 critical. 14 of them were published after the end of life of the affected cycle and will not get an official patch. The next major version is Python 3. See Python 3 →
Python 2.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 2.7 | Jul 3, 2010 | — | Jan 1, 2020 | 2.7.18 | EOL | |
| 2.6 | Oct 1, 2008 | — | Oct 29, 2013 | 2.6.9 | EOL |
CVEs affecting Python 2.x (29)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-15308 | HIGH | 7.5 | 0.63% | — | 2.7 | The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark… | Jul 9, 2026 |
| CVE-2026-15308 | HIGH | 7.5 | 0.63% | — | 2.6 | The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark… | Jul 9, 2026 |
| CVE-2026-4360 | MEDIUM | 5.3 | 0.48% | — | 2.6 | In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected sy… | Jun 30, 2026 |
| CVE-2026-4360 | MEDIUM | 5.3 | 0.48% | — | 2.7 | In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected sy… | Jun 30, 2026 |
| CVE-2026-0864 | MEDIUM | 5.5 | 0.12% | — | 2.7 | When using the "configparser" module to write configuration files containing multi-line text values with carriage return… | Jun 23, 2026 |
| CVE-2026-0864 | MEDIUM | 5.5 | 0.12% | — | 2.6 | When using the "configparser" module to write configuration files containing multi-line text values with carriage return… | Jun 23, 2026 |
| CVE-2026-7210 | CRITICAL | 9.8 | 1.35% | — | 2.6 | `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow… | May 11, 2026 |
| CVE-2026-7210 | CRITICAL | 9.8 | 1.35% | — | 2.7 | `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow… | May 11, 2026 |
| CVE-2026-3087 | HIGH | 7.5 | 0.73% | — | 2.7 | If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th… | Apr 27, 2026 |
| CVE-2026-3087 | HIGH | 7.5 | 0.73% | — | 2.6 | If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th… | Apr 27, 2026 |
| CVE-2026-6019 | MEDIUM | 6.1 | 0.58% | — | 2.6 | http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It … | Apr 22, 2026 |
| CVE-2026-6019 | MEDIUM | 6.1 | 0.58% | — | 2.7 | http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It … | Apr 22, 2026 |
| CVE-2026-4519 | LOW | 3.3 | 0.39% | — | 2.7 | The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer… | Mar 20, 2026 |
| CVE-2026-4519 | LOW | 3.3 | 0.39% | — | 2.6 | The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer… | Mar 20, 2026 |
| CVE-2026-4224 | HIGH | 7.5 | 0.69% | — | 2.6 | When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply … | Mar 16, 2026 |
| CVE-2026-4224 | HIGH | 7.5 | 0.69% | — | 2.7 | When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply … | Mar 16, 2026 |
| CVE-2026-3644 | HIGH | 7.5 | 0.47% | — | 2.7 | The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()… | Mar 16, 2026 |
| CVE-2026-3644 | HIGH | 7.5 | 0.47% | — | 2.6 | The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()… | Mar 16, 2026 |
| CVE-2025-13462 | CRITICAL | 9.8 | 0.16% | — | 2.6 | The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi… | Mar 12, 2026 |
| CVE-2025-13462 | CRITICAL | 9.8 | 0.16% | — | 2.7 | The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi… | Mar 12, 2026 |
| CVE-2025-12781 | MEDIUM | 5.3 | 0.56% | — | 2.6 | When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the… | Jan 21, 2026 |
| CVE-2025-12781 | MEDIUM | 5.3 | 0.56% | — | 2.7 | When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the… | Jan 21, 2026 |
| CVE-2025-13837 | MEDIUM | 5.5 | 0.22% | — | 2.7 | When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file… | Dec 1, 2025 |
| CVE-2025-13837 | MEDIUM | 5.5 | 0.22% | — | 2.6 | When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file… | Dec 1, 2025 |
| CVE-2025-13836 | HIGH | 7.5 | 1.63% | — | 2.7 | When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content… | Dec 1, 2025 |
| CVE-2025-13836 | HIGH | 7.5 | 1.63% | — | 2.6 | When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content… | Dec 1, 2025 |
| CVE-2025-6075 | MEDIUM | 5.5 | 0.14% | — | 2.6 | If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding env… | Oct 31, 2025 |
| CVE-2025-6075 | MEDIUM | 5.5 | 0.14% | — | 2.7 | If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding env… | Oct 31, 2025 |
| CVE-2016-2183 | HIGH | 7.5 | 94.69% | — | 2.7 | The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a bi… | Sep 1, 2016 |
Python 2.x is EOL — migrate to Python 3.x
Python 3.x is the next major release. Plan your upgrade before Python 2.x stops receiving security patches.
Add a Python 2 EOL badge to your README
Show your users which Python version your project runs and whether it is still supported. The badge updates automatically. More formats and options →
[](https://eolcanary.com/explore/python/2)Frequently asked questions
Is Python 2 end of life?
Yes. All Python 2.x releases have reached end of life and no longer receive security patches. There are 15 known CVEs affecting Python 2.x, including 2 critical. Migrate to Python 3.x as soon as possible.
What CVEs affect Python 2?
There are 15 CVEs tracked for Python 2.x, including 2 critical severity issues. See the full list above with CVSS and EPSS scores.
What is the latest Python 2 version?
The latest Python 2.x patch release is 2.7.18, released on April 19, 2020. Always run the latest patch to benefit from all security fixes.
How to migrate from Python 2 to Python 3?
To migrate from Python 2 to Python 3: (1) review the official Python 3 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.
Is it safe to run Python 2 in production?
No. Python 2 has reached end of life and security vulnerabilities are no longer patched. Upgrade to a supported version immediately.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
