Python 2.x — End of Life

EOL Critical risk
EOL: Jan 1, 20202 releases in this series15 CVEs

Python 2.x reached end of life on Jan 1, 2020, 2471 days ago, and no longer receives security fixes. The most recent release in this series is 2.7.18. 15 CVEs are tracked for this series, including 2 critical. 14 of them were published after the end of life of the affected cycle and will not get an official patch. The next major version is Python 3. See Python 3 →

Python 2.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
2.7Jul 3, 2010—Jan 1, 20202.7.18EOL
2.6Oct 1, 2008—Oct 29, 20132.6.9EOL

CVEs affecting Python 2.x (29)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2026-15308HIGH7.50.63%—2.7The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark…Jul 9, 2026
CVE-2026-15308HIGH7.50.63%—2.6The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark…Jul 9, 2026
CVE-2026-4360MEDIUM5.30.48%—2.6In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected sy…Jun 30, 2026
CVE-2026-4360MEDIUM5.30.48%—2.7In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected sy…Jun 30, 2026
CVE-2026-0864MEDIUM5.50.12%—2.7When using the "configparser" module to write configuration files containing multi-line text values with carriage return…Jun 23, 2026
CVE-2026-0864MEDIUM5.50.12%—2.6When using the "configparser" module to write configuration files containing multi-line text values with carriage return…Jun 23, 2026
CVE-2026-7210CRITICAL9.81.35%—2.6`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow…May 11, 2026
CVE-2026-7210CRITICAL9.81.35%—2.7`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow…May 11, 2026
CVE-2026-3087HIGH7.50.73%—2.7If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th…Apr 27, 2026
CVE-2026-3087HIGH7.50.73%—2.6If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th…Apr 27, 2026
CVE-2026-6019MEDIUM6.10.58%—2.6http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It …Apr 22, 2026
CVE-2026-6019MEDIUM6.10.58%—2.7http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It …Apr 22, 2026
CVE-2026-4519LOW3.30.39%—2.7The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer…Mar 20, 2026
CVE-2026-4519LOW3.30.39%—2.6The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer…Mar 20, 2026
CVE-2026-4224HIGH7.50.69%—2.6When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply …Mar 16, 2026
CVE-2026-4224HIGH7.50.69%—2.7When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply …Mar 16, 2026
CVE-2026-3644HIGH7.50.47%—2.7The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()…Mar 16, 2026
CVE-2026-3644HIGH7.50.47%—2.6The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()…Mar 16, 2026
CVE-2025-13462CRITICAL9.80.16%—2.6The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi…Mar 12, 2026
CVE-2025-13462CRITICAL9.80.16%—2.7The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi…Mar 12, 2026
CVE-2025-12781MEDIUM5.30.56%—2.6When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the…Jan 21, 2026
CVE-2025-12781MEDIUM5.30.56%—2.7When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the…Jan 21, 2026
CVE-2025-13837MEDIUM5.50.22%—2.7When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file…Dec 1, 2025
CVE-2025-13837MEDIUM5.50.22%—2.6When loading a plist file, the plistlib module reads data in size specified by the file itself, meaning a malicious file…Dec 1, 2025
CVE-2025-13836HIGH7.51.63%—2.7When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content…Dec 1, 2025
CVE-2025-13836HIGH7.51.63%—2.6When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content…Dec 1, 2025
CVE-2025-6075MEDIUM5.50.14%—2.6If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding env…Oct 31, 2025
CVE-2025-6075MEDIUM5.50.14%—2.7If the value passed to os.path.expandvars() is user-controlled a performance degradation is possible when expanding env…Oct 31, 2025
CVE-2016-2183HIGH7.594.69%—2.7The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a bi…Sep 1, 2016

Python 2.x is EOL — migrate to Python 3.x

Python 3.x is the next major release. Plan your upgrade before Python 2.x stops receiving security patches.

See Python 3.x

Add a Python 2 EOL badge to your README

Show your users which Python version your project runs and whether it is still supported. The badge updates automatically. More formats and options →

Python 2 EOL status
[![Python 2 EOL status](https://eolcanary.com/badge/python/2.svg)](https://eolcanary.com/explore/python/2)

Frequently asked questions

Is Python 2 end of life?

Yes. All Python 2.x releases have reached end of life and no longer receive security patches. There are 15 known CVEs affecting Python 2.x, including 2 critical. Migrate to Python 3.x as soon as possible.

What CVEs affect Python 2?

There are 15 CVEs tracked for Python 2.x, including 2 critical severity issues. See the full list above with CVSS and EPSS scores.

What is the latest Python 2 version?

The latest Python 2.x patch release is 2.7.18, released on April 19, 2020. Always run the latest patch to benefit from all security fixes.

How to migrate from Python 2 to Python 3?

To migrate from Python 2 to Python 3: (1) review the official Python 3 migration guide for breaking changes, (2) update dependencies and configuration accordingly, (3) test thoroughly in a staging environment, (4) deploy with a rollback plan. Starting early gives you time to resolve compatibility issues before your current version reaches end of life.

Is it safe to run Python 2 in production?

No. Python 2 has reached end of life and security vulnerabilities are no longer patched. Upgrade to a supported version immediately.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA