Python 3.x — End of Life

Active Critical risk
EOL: Oct 31, 2030in 1559d15 releases in this series156 CVEs

Python 3.x — All releases

VersionReleasedActive supportEOL dateLatest patchStatusAlert me
3.14Oct 7, 2025Oct 1, 2027Oct 31, 20303.14.6Active
3.13Oct 7, 2024Oct 1, 2026Oct 31, 20293.13.14Active
3.12Oct 2, 2023Apr 2, 2025Oct 31, 20283.12.13Active
3.11Oct 24, 2022Apr 1, 2024Oct 31, 20273.11.15Active
3.10Oct 4, 2021Apr 5, 2023Oct 31, 20263.10.20Active
3.9Oct 5, 2020May 17, 2022Oct 31, 20253.9.25EOL
3.8Oct 14, 2019May 3, 2021Oct 7, 20243.8.20EOL
3.7Jun 27, 2018Jun 27, 2020Jun 27, 20233.7.17EOL
3.6Dec 23, 2016Dec 24, 2018Dec 23, 20213.6.15EOL
3.5Sep 13, 2015Sep 30, 20203.5.10EOL
3.4Mar 16, 2014Mar 18, 20193.4.10EOL
3.3Sep 29, 2012Sep 29, 20173.3.7EOL
3.2Feb 20, 2011Feb 20, 20163.2.6EOL
3.1Jun 27, 2009Apr 9, 20123.1.5EOL
3.0Dec 3, 2008Jun 27, 20093.0.1EOL

CVEs affecting Python 3.x (156)

CVESeverityCVSSEPSSKEVCycleDescriptionPublished
CVE-2026-15308HIGH7.50.55%3.8The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark…Jul 9, 2026
CVE-2026-15308HIGH7.50.55%3.7The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark…Jul 9, 2026
CVE-2026-15308HIGH7.50.55%3.5The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark…Jul 9, 2026
CVE-2026-15308HIGH7.50.55%3.13The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark…Jul 9, 2026
CVE-2026-15308HIGH7.50.55%3.6The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark…Jul 9, 2026
CVE-2026-15308HIGH7.50.55%3.12The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark…Jul 9, 2026
CVE-2026-15308HIGH7.50.55%3.0The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark…Jul 9, 2026
CVE-2026-15308HIGH7.50.55%3.3The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark…Jul 9, 2026
CVE-2026-15308HIGH7.50.55%3.1The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark…Jul 9, 2026
CVE-2026-15308HIGH7.50.55%3.9The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark…Jul 9, 2026
CVE-2026-15308HIGH7.50.55%3.11The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark…Jul 9, 2026
CVE-2026-15308HIGH7.50.55%3.2The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark…Jul 9, 2026
CVE-2026-15308HIGH7.50.55%3.4The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark…Jul 9, 2026
CVE-2026-15308HIGH7.50.55%3.10The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark…Jul 9, 2026
CVE-2026-15308HIGH7.50.55%3.14The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark…Jul 9, 2026
CVE-2026-4360MEDIUM5.30.26%3.0In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected sy…Jun 30, 2026
CVE-2026-4360MEDIUM5.30.26%3.1In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected sy…Jun 30, 2026
CVE-2026-7210CRITICAL9.80.79%3.10`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow…May 11, 2026
CVE-2026-7210CRITICAL9.80.79%3.8`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow…May 11, 2026
CVE-2026-7210CRITICAL9.80.79%3.6`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow…May 11, 2026
CVE-2026-7210CRITICAL9.80.79%3.3`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow…May 11, 2026
CVE-2026-7210CRITICAL9.80.79%3.5`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow…May 11, 2026
CVE-2026-7210CRITICAL9.80.79%3.12`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow…May 11, 2026
CVE-2026-7210CRITICAL9.80.79%3.0`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow…May 11, 2026
CVE-2026-7210CRITICAL9.80.79%3.9`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow…May 11, 2026
CVE-2026-7210CRITICAL9.80.79%3.7`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow…May 11, 2026
CVE-2026-7210CRITICAL9.80.79%3.4`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow…May 11, 2026
CVE-2026-7210CRITICAL9.80.79%3.13`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow…May 11, 2026
CVE-2026-7210CRITICAL9.80.79%3.1`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow…May 11, 2026
CVE-2026-7210CRITICAL9.80.79%3.2`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow…May 11, 2026
CVE-2026-7210CRITICAL9.80.79%3.11`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow…May 11, 2026
CVE-2026-7210CRITICAL9.80.79%3.14`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow…May 11, 2026
CVE-2026-3087HIGH7.50.53%3.1If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th…Apr 27, 2026
CVE-2026-3087HIGH7.50.53%3.9If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th…Apr 27, 2026
CVE-2026-3087HIGH7.50.53%3.14If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th…Apr 27, 2026
CVE-2026-3087HIGH7.50.53%3.12If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th…Apr 27, 2026
CVE-2026-3087HIGH7.50.53%3.7If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th…Apr 27, 2026
CVE-2026-3087HIGH7.50.53%3.13If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th…Apr 27, 2026
CVE-2026-3087HIGH7.50.53%3.0If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th…Apr 27, 2026
CVE-2026-3087HIGH7.50.53%3.11If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th…Apr 27, 2026
CVE-2026-3087HIGH7.50.53%3.6If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th…Apr 27, 2026
CVE-2026-3087HIGH7.50.53%3.10If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th…Apr 27, 2026
CVE-2026-3087HIGH7.50.53%3.3If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th…Apr 27, 2026
CVE-2026-3087HIGH7.50.53%3.5If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th…Apr 27, 2026
CVE-2026-3087HIGH7.50.53%3.8If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th…Apr 27, 2026
CVE-2026-3087HIGH7.50.53%3.4If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th…Apr 27, 2026
CVE-2026-3087HIGH7.50.53%3.2If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th…Apr 27, 2026
CVE-2026-6019MEDIUM6.10.23%3.7http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It …Apr 22, 2026
CVE-2026-6019MEDIUM6.10.23%3.0http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It …Apr 22, 2026
CVE-2026-6019MEDIUM6.10.23%3.10http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It …Apr 22, 2026
CVE-2026-6019MEDIUM6.10.23%3.4http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It …Apr 22, 2026
CVE-2026-6019MEDIUM6.10.23%3.1http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It …Apr 22, 2026
CVE-2026-6019MEDIUM6.10.23%3.6http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It …Apr 22, 2026
CVE-2026-6019MEDIUM6.10.23%3.13http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It …Apr 22, 2026
CVE-2026-6019MEDIUM6.10.23%3.9http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It …Apr 22, 2026
CVE-2026-6019MEDIUM6.10.23%3.2http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It …Apr 22, 2026
CVE-2026-6019MEDIUM6.10.23%3.14http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It …Apr 22, 2026
CVE-2026-6019MEDIUM6.10.23%3.11http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It …Apr 22, 2026
CVE-2026-6019MEDIUM6.10.23%3.12http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It …Apr 22, 2026
CVE-2026-6019MEDIUM6.10.23%3.5http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It …Apr 22, 2026
CVE-2026-6019MEDIUM6.10.23%3.3http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It …Apr 22, 2026
CVE-2026-6019MEDIUM6.10.23%3.8http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It …Apr 22, 2026
CVE-2026-4519LOW3.30.31%3.1The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer…Mar 20, 2026
CVE-2026-4519LOW3.30.31%3.0The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer…Mar 20, 2026
CVE-2026-4519LOW3.30.31%3.12The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer…Mar 20, 2026
CVE-2026-4519LOW3.30.31%3.13The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer…Mar 20, 2026
CVE-2026-4519LOW3.30.31%3.10The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer…Mar 20, 2026
CVE-2026-4519LOW3.30.31%3.5The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer…Mar 20, 2026
CVE-2026-4519LOW3.30.31%3.2The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer…Mar 20, 2026
CVE-2026-4519LOW3.30.31%3.9The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer…Mar 20, 2026
CVE-2026-4519LOW3.30.31%3.4The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer…Mar 20, 2026
CVE-2026-4519LOW3.30.31%3.8The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer…Mar 20, 2026
CVE-2026-4519LOW3.30.31%3.3The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer…Mar 20, 2026
CVE-2026-4519LOW3.30.31%3.6The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer…Mar 20, 2026
CVE-2026-4519LOW3.30.31%3.11The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer…Mar 20, 2026
CVE-2026-4519LOW3.30.31%3.7The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer…Mar 20, 2026
CVE-2026-4519LOW3.30.31%3.14The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer…Mar 20, 2026
CVE-2026-4224HIGH7.50.62%3.2When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply …Mar 16, 2026
CVE-2026-4224HIGH7.50.62%3.7When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply …Mar 16, 2026
CVE-2026-4224HIGH7.50.62%3.1When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply …Mar 16, 2026
CVE-2026-4224HIGH7.50.62%3.9When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply …Mar 16, 2026
CVE-2026-4224HIGH7.50.62%3.8When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply …Mar 16, 2026
CVE-2026-4224HIGH7.50.62%3.3When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply …Mar 16, 2026
CVE-2026-4224HIGH7.50.62%3.5When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply …Mar 16, 2026
CVE-2026-4224HIGH7.50.62%3.6When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply …Mar 16, 2026
CVE-2026-4224HIGH7.50.62%3.13When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply …Mar 16, 2026
CVE-2026-4224HIGH7.50.62%3.10When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply …Mar 16, 2026
CVE-2026-4224HIGH7.50.62%3.14When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply …Mar 16, 2026
CVE-2026-4224HIGH7.50.62%3.0When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply …Mar 16, 2026
CVE-2026-4224HIGH7.50.62%3.4When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply …Mar 16, 2026
CVE-2026-3644HIGH7.50.42%3.2The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()…Mar 16, 2026
CVE-2026-3644HIGH7.50.42%3.6The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()…Mar 16, 2026
CVE-2026-3644HIGH7.50.42%3.13The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()…Mar 16, 2026
CVE-2026-3644HIGH7.50.42%3.9The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()…Mar 16, 2026
CVE-2026-3644HIGH7.50.42%3.4The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()…Mar 16, 2026
CVE-2026-3644HIGH7.50.42%3.0The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()…Mar 16, 2026
CVE-2026-3644HIGH7.50.42%3.1The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()…Mar 16, 2026
CVE-2026-3644HIGH7.50.42%3.5The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()…Mar 16, 2026
CVE-2026-3644HIGH7.50.42%3.8The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()…Mar 16, 2026
CVE-2026-3644HIGH7.50.42%3.7The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()…Mar 16, 2026
CVE-2026-3644HIGH7.50.42%3.12The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()…Mar 16, 2026
CVE-2026-3644HIGH7.50.42%3.3The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()…Mar 16, 2026
CVE-2026-3644HIGH7.50.42%3.10The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()…Mar 16, 2026
CVE-2026-3644HIGH7.50.42%3.11The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()…Mar 16, 2026
CVE-2026-3644HIGH7.50.42%3.14The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()…Mar 16, 2026
CVE-2025-13462CRITICAL9.80.16%3.4The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi…Mar 12, 2026
CVE-2025-13462CRITICAL9.80.16%3.11The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi…Mar 12, 2026
CVE-2025-13462CRITICAL9.80.16%3.12The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi…Mar 12, 2026
CVE-2025-13462CRITICAL9.80.16%3.2The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi…Mar 12, 2026
CVE-2025-13462CRITICAL9.80.16%3.10The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi…Mar 12, 2026
CVE-2025-13462CRITICAL9.80.16%3.9The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi…Mar 12, 2026
CVE-2025-13462CRITICAL9.80.16%3.13The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi…Mar 12, 2026
CVE-2025-13462CRITICAL9.80.16%3.6The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi…Mar 12, 2026
CVE-2025-13462CRITICAL9.80.16%3.5The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi…Mar 12, 2026
CVE-2025-13462CRITICAL9.80.16%3.7The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi…Mar 12, 2026
CVE-2025-13462CRITICAL9.80.16%3.0The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi…Mar 12, 2026
CVE-2025-13462CRITICAL9.80.16%3.3The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi…Mar 12, 2026
CVE-2025-13462CRITICAL9.80.16%3.8The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi…Mar 12, 2026
CVE-2025-13462CRITICAL9.80.16%3.1The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi…Mar 12, 2026
CVE-2025-13462CRITICAL9.80.16%3.14The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi…Mar 12, 2026
CVE-2025-12781MEDIUM5.30.51%3.2When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the…Jan 21, 2026
CVE-2025-12781MEDIUM5.30.51%3.1When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the…Jan 21, 2026
CVE-2025-12781MEDIUM5.30.51%3.4When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the…Jan 21, 2026
CVE-2025-12781MEDIUM5.30.51%3.5When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the…Jan 21, 2026
CVE-2025-12781MEDIUM5.30.51%3.8When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the…Jan 21, 2026
CVE-2025-12781MEDIUM5.30.51%3.10When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the…Jan 21, 2026
CVE-2025-12781MEDIUM5.30.51%3.3When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the…Jan 21, 2026
CVE-2025-12781MEDIUM5.30.51%3.13When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the…Jan 21, 2026
CVE-2025-12781MEDIUM5.30.51%3.6When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the…Jan 21, 2026
CVE-2025-12781MEDIUM5.30.51%3.11When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the…Jan 21, 2026
CVE-2025-12781MEDIUM5.30.51%3.12When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the…Jan 21, 2026
CVE-2025-12781MEDIUM5.30.51%3.14When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the…Jan 21, 2026
CVE-2025-12781MEDIUM5.30.51%3.7When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the…Jan 21, 2026
CVE-2025-12781MEDIUM5.30.51%3.0When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the…Jan 21, 2026
CVE-2025-12781MEDIUM5.30.51%3.9When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the…Jan 21, 2026
CVE-2025-13836HIGH7.51.52%3.12When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content…Dec 1, 2025
CVE-2025-13836HIGH7.51.52%3.6When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content…Dec 1, 2025
CVE-2025-13836HIGH7.51.52%3.13When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content…Dec 1, 2025
CVE-2025-13836HIGH7.51.52%3.3When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content…Dec 1, 2025
CVE-2025-13836HIGH7.51.52%3.5When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content…Dec 1, 2025
CVE-2025-13836HIGH7.51.52%3.10When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content…Dec 1, 2025
CVE-2025-13836HIGH7.51.52%3.8When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content…Dec 1, 2025
CVE-2025-13836HIGH7.51.52%3.14When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content…Dec 1, 2025
CVE-2025-13836HIGH7.51.52%3.11When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content…Dec 1, 2025
CVE-2025-13836HIGH7.51.52%3.7When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content…Dec 1, 2025
CVE-2025-13836HIGH7.51.52%3.0When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content…Dec 1, 2025
CVE-2025-13836HIGH7.51.52%3.1When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content…Dec 1, 2025
CVE-2025-13836HIGH7.51.52%3.9When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content…Dec 1, 2025
CVE-2025-13836HIGH7.51.52%3.4When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content…Dec 1, 2025
CVE-2025-13836HIGH7.51.52%3.2When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content…Dec 1, 2025
CVE-2018-25032HIGH7.550.84%3.7zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matche…Mar 25, 2022
CVE-2018-25032HIGH7.550.84%3.10zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matche…Mar 25, 2022
CVE-2018-25032HIGH7.550.84%3.8zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matche…Mar 25, 2022
CVE-2018-25032HIGH7.550.84%3.9zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matche…Mar 25, 2022
CVE-2016-2183HIGH7.595.71%3.4The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a bi…Sep 1, 2016
CVE-2016-2183HIGH7.595.71%3.5The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a bi…Sep 1, 2016

Frequently asked questions

Is Python 3 end of life?

Partially. Some Python 3.x releases have reached EOL. Check the version table above for the exact status of each sub-release.

What CVEs affect Python 3?

There are 156 CVEs tracked for Python 3.x, including 30 critical severity issues. See the full list above with CVSS and EPSS scores.

What is the latest Python 3 version?

The latest Python 3.x patch release is 3.14.6, released on June 10, 2026. Always run the latest patch to benefit from all security fixes.

When was Python 3 first released?

Python 3.0 was initially released on October 7, 2025. See the full version timeline in the table above.

Is it safe to run Python 3 in production?

Python 3 is still supported and safe for production use until October 31, 2030. Ensure you are running the latest patch version (3.14.6) to have all security fixes applied.

Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA