Python 3.x — End of Life
Active Critical riskPython 3.x — All releases
| Version | Released | Active support | EOL date | Latest patch | Status | Alert me |
|---|---|---|---|---|---|---|
| 3.14 | Oct 7, 2025 | Oct 1, 2027 | Oct 31, 2030 | 3.14.6 | Active | |
| 3.13 | Oct 7, 2024 | Oct 1, 2026 | Oct 31, 2029 | 3.13.14 | Active | |
| 3.12 | Oct 2, 2023 | Apr 2, 2025 | Oct 31, 2028 | 3.12.13 | Active | |
| 3.11 | Oct 24, 2022 | Apr 1, 2024 | Oct 31, 2027 | 3.11.15 | Active | |
| 3.10 | Oct 4, 2021 | Apr 5, 2023 | Oct 31, 2026 | 3.10.20 | Active | |
| 3.9 | Oct 5, 2020 | May 17, 2022 | Oct 31, 2025 | 3.9.25 | EOL | |
| 3.8 | Oct 14, 2019 | May 3, 2021 | Oct 7, 2024 | 3.8.20 | EOL | |
| 3.7 | Jun 27, 2018 | Jun 27, 2020 | Jun 27, 2023 | 3.7.17 | EOL | |
| 3.6 | Dec 23, 2016 | Dec 24, 2018 | Dec 23, 2021 | 3.6.15 | EOL | |
| 3.5 | Sep 13, 2015 | — | Sep 30, 2020 | 3.5.10 | EOL | |
| 3.4 | Mar 16, 2014 | — | Mar 18, 2019 | 3.4.10 | EOL | |
| 3.3 | Sep 29, 2012 | — | Sep 29, 2017 | 3.3.7 | EOL | |
| 3.2 | Feb 20, 2011 | — | Feb 20, 2016 | 3.2.6 | EOL | |
| 3.1 | Jun 27, 2009 | — | Apr 9, 2012 | 3.1.5 | EOL | |
| 3.0 | Dec 3, 2008 | — | Jun 27, 2009 | 3.0.1 | EOL |
CVEs affecting Python 3.x (156)
| CVE | Severity | CVSS | EPSS | KEV | Cycle | Description | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-15308 | HIGH | 7.5 | 0.55% | — | 3.8 | The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark… | Jul 9, 2026 |
| CVE-2026-15308 | HIGH | 7.5 | 0.55% | — | 3.7 | The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark… | Jul 9, 2026 |
| CVE-2026-15308 | HIGH | 7.5 | 0.55% | — | 3.5 | The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark… | Jul 9, 2026 |
| CVE-2026-15308 | HIGH | 7.5 | 0.55% | — | 3.13 | The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark… | Jul 9, 2026 |
| CVE-2026-15308 | HIGH | 7.5 | 0.55% | — | 3.6 | The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark… | Jul 9, 2026 |
| CVE-2026-15308 | HIGH | 7.5 | 0.55% | — | 3.12 | The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark… | Jul 9, 2026 |
| CVE-2026-15308 | HIGH | 7.5 | 0.55% | — | 3.0 | The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark… | Jul 9, 2026 |
| CVE-2026-15308 | HIGH | 7.5 | 0.55% | — | 3.3 | The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark… | Jul 9, 2026 |
| CVE-2026-15308 | HIGH | 7.5 | 0.55% | — | 3.1 | The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark… | Jul 9, 2026 |
| CVE-2026-15308 | HIGH | 7.5 | 0.55% | — | 3.9 | The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark… | Jul 9, 2026 |
| CVE-2026-15308 | HIGH | 7.5 | 0.55% | — | 3.11 | The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark… | Jul 9, 2026 |
| CVE-2026-15308 | HIGH | 7.5 | 0.55% | — | 3.2 | The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark… | Jul 9, 2026 |
| CVE-2026-15308 | HIGH | 7.5 | 0.55% | — | 3.4 | The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark… | Jul 9, 2026 |
| CVE-2026-15308 | HIGH | 7.5 | 0.55% | — | 3.10 | The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark… | Jul 9, 2026 |
| CVE-2026-15308 | HIGH | 7.5 | 0.55% | — | 3.14 | The incremental HTML parser (html.parser.HTMLParser) allows for CPU denial-of-service through repeated unterminated mark… | Jul 9, 2026 |
| CVE-2026-4360 | MEDIUM | 5.3 | 0.26% | — | 3.0 | In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected sy… | Jun 30, 2026 |
| CVE-2026-4360 | MEDIUM | 5.3 | 0.26% | — | 3.1 | In the Tarfile.extract() function, the filter parameter is not passed properly when extracting hardlinks. An affected sy… | Jun 30, 2026 |
| CVE-2026-7210 | CRITICAL | 9.8 | 0.79% | — | 3.10 | `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow… | May 11, 2026 |
| CVE-2026-7210 | CRITICAL | 9.8 | 0.79% | — | 3.8 | `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow… | May 11, 2026 |
| CVE-2026-7210 | CRITICAL | 9.8 | 0.79% | — | 3.6 | `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow… | May 11, 2026 |
| CVE-2026-7210 | CRITICAL | 9.8 | 0.79% | — | 3.3 | `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow… | May 11, 2026 |
| CVE-2026-7210 | CRITICAL | 9.8 | 0.79% | — | 3.5 | `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow… | May 11, 2026 |
| CVE-2026-7210 | CRITICAL | 9.8 | 0.79% | — | 3.12 | `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow… | May 11, 2026 |
| CVE-2026-7210 | CRITICAL | 9.8 | 0.79% | — | 3.0 | `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow… | May 11, 2026 |
| CVE-2026-7210 | CRITICAL | 9.8 | 0.79% | — | 3.9 | `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow… | May 11, 2026 |
| CVE-2026-7210 | CRITICAL | 9.8 | 0.79% | — | 3.7 | `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow… | May 11, 2026 |
| CVE-2026-7210 | CRITICAL | 9.8 | 0.79% | — | 3.4 | `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow… | May 11, 2026 |
| CVE-2026-7210 | CRITICAL | 9.8 | 0.79% | — | 3.13 | `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow… | May 11, 2026 |
| CVE-2026-7210 | CRITICAL | 9.8 | 0.79% | — | 3.1 | `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow… | May 11, 2026 |
| CVE-2026-7210 | CRITICAL | 9.8 | 0.79% | — | 3.2 | `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow… | May 11, 2026 |
| CVE-2026-7210 | CRITICAL | 9.8 | 0.79% | — | 3.11 | `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow… | May 11, 2026 |
| CVE-2026-7210 | CRITICAL | 9.8 | 0.79% | — | 3.14 | `xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allow… | May 11, 2026 |
| CVE-2026-3087 | HIGH | 7.5 | 0.53% | — | 3.1 | If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th… | Apr 27, 2026 |
| CVE-2026-3087 | HIGH | 7.5 | 0.53% | — | 3.9 | If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th… | Apr 27, 2026 |
| CVE-2026-3087 | HIGH | 7.5 | 0.53% | — | 3.14 | If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th… | Apr 27, 2026 |
| CVE-2026-3087 | HIGH | 7.5 | 0.53% | — | 3.12 | If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th… | Apr 27, 2026 |
| CVE-2026-3087 | HIGH | 7.5 | 0.53% | — | 3.7 | If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th… | Apr 27, 2026 |
| CVE-2026-3087 | HIGH | 7.5 | 0.53% | — | 3.13 | If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th… | Apr 27, 2026 |
| CVE-2026-3087 | HIGH | 7.5 | 0.53% | — | 3.0 | If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th… | Apr 27, 2026 |
| CVE-2026-3087 | HIGH | 7.5 | 0.53% | — | 3.11 | If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th… | Apr 27, 2026 |
| CVE-2026-3087 | HIGH | 7.5 | 0.53% | — | 3.6 | If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th… | Apr 27, 2026 |
| CVE-2026-3087 | HIGH | 7.5 | 0.53% | — | 3.10 | If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th… | Apr 27, 2026 |
| CVE-2026-3087 | HIGH | 7.5 | 0.53% | — | 3.3 | If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th… | Apr 27, 2026 |
| CVE-2026-3087 | HIGH | 7.5 | 0.53% | — | 3.5 | If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th… | Apr 27, 2026 |
| CVE-2026-3087 | HIGH | 7.5 | 0.53% | — | 3.8 | If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th… | Apr 27, 2026 |
| CVE-2026-3087 | HIGH | 7.5 | 0.53% | — | 3.4 | If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th… | Apr 27, 2026 |
| CVE-2026-3087 | HIGH | 7.5 | 0.53% | — | 3.2 | If `shutil.unpack_archive()` is given a ZIP archive with an absolute Windows path containing a drive (`C:\\...`) then th… | Apr 27, 2026 |
| CVE-2026-6019 | MEDIUM | 6.1 | 0.23% | — | 3.7 | http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It … | Apr 22, 2026 |
| CVE-2026-6019 | MEDIUM | 6.1 | 0.23% | — | 3.0 | http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It … | Apr 22, 2026 |
| CVE-2026-6019 | MEDIUM | 6.1 | 0.23% | — | 3.10 | http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It … | Apr 22, 2026 |
| CVE-2026-6019 | MEDIUM | 6.1 | 0.23% | — | 3.4 | http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It … | Apr 22, 2026 |
| CVE-2026-6019 | MEDIUM | 6.1 | 0.23% | — | 3.1 | http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It … | Apr 22, 2026 |
| CVE-2026-6019 | MEDIUM | 6.1 | 0.23% | — | 3.6 | http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It … | Apr 22, 2026 |
| CVE-2026-6019 | MEDIUM | 6.1 | 0.23% | — | 3.13 | http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It … | Apr 22, 2026 |
| CVE-2026-6019 | MEDIUM | 6.1 | 0.23% | — | 3.9 | http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It … | Apr 22, 2026 |
| CVE-2026-6019 | MEDIUM | 6.1 | 0.23% | — | 3.2 | http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It … | Apr 22, 2026 |
| CVE-2026-6019 | MEDIUM | 6.1 | 0.23% | — | 3.14 | http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It … | Apr 22, 2026 |
| CVE-2026-6019 | MEDIUM | 6.1 | 0.23% | — | 3.11 | http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It … | Apr 22, 2026 |
| CVE-2026-6019 | MEDIUM | 6.1 | 0.23% | — | 3.12 | http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It … | Apr 22, 2026 |
| CVE-2026-6019 | MEDIUM | 6.1 | 0.23% | — | 3.5 | http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It … | Apr 22, 2026 |
| CVE-2026-6019 | MEDIUM | 6.1 | 0.23% | — | 3.3 | http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It … | Apr 22, 2026 |
| CVE-2026-6019 | MEDIUM | 6.1 | 0.23% | — | 3.8 | http.cookies.Morsel.js_output() returns an inline <script> snippet and only escapes " for JavaScript string context. It … | Apr 22, 2026 |
| CVE-2026-4519 | LOW | 3.3 | 0.31% | — | 3.1 | The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer… | Mar 20, 2026 |
| CVE-2026-4519 | LOW | 3.3 | 0.31% | — | 3.0 | The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer… | Mar 20, 2026 |
| CVE-2026-4519 | LOW | 3.3 | 0.31% | — | 3.12 | The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer… | Mar 20, 2026 |
| CVE-2026-4519 | LOW | 3.3 | 0.31% | — | 3.13 | The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer… | Mar 20, 2026 |
| CVE-2026-4519 | LOW | 3.3 | 0.31% | — | 3.10 | The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer… | Mar 20, 2026 |
| CVE-2026-4519 | LOW | 3.3 | 0.31% | — | 3.5 | The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer… | Mar 20, 2026 |
| CVE-2026-4519 | LOW | 3.3 | 0.31% | — | 3.2 | The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer… | Mar 20, 2026 |
| CVE-2026-4519 | LOW | 3.3 | 0.31% | — | 3.9 | The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer… | Mar 20, 2026 |
| CVE-2026-4519 | LOW | 3.3 | 0.31% | — | 3.4 | The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer… | Mar 20, 2026 |
| CVE-2026-4519 | LOW | 3.3 | 0.31% | — | 3.8 | The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer… | Mar 20, 2026 |
| CVE-2026-4519 | LOW | 3.3 | 0.31% | — | 3.3 | The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer… | Mar 20, 2026 |
| CVE-2026-4519 | LOW | 3.3 | 0.31% | — | 3.6 | The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer… | Mar 20, 2026 |
| CVE-2026-4519 | LOW | 3.3 | 0.31% | — | 3.11 | The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer… | Mar 20, 2026 |
| CVE-2026-4519 | LOW | 3.3 | 0.31% | — | 3.7 | The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer… | Mar 20, 2026 |
| CVE-2026-4519 | LOW | 3.3 | 0.31% | — | 3.14 | The webbrowser.open() API would accept leading dashes in the URL which could be handled as command line options for cer… | Mar 20, 2026 |
| CVE-2026-4224 | HIGH | 7.5 | 0.62% | — | 3.2 | When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply … | Mar 16, 2026 |
| CVE-2026-4224 | HIGH | 7.5 | 0.62% | — | 3.7 | When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply … | Mar 16, 2026 |
| CVE-2026-4224 | HIGH | 7.5 | 0.62% | — | 3.1 | When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply … | Mar 16, 2026 |
| CVE-2026-4224 | HIGH | 7.5 | 0.62% | — | 3.9 | When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply … | Mar 16, 2026 |
| CVE-2026-4224 | HIGH | 7.5 | 0.62% | — | 3.8 | When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply … | Mar 16, 2026 |
| CVE-2026-4224 | HIGH | 7.5 | 0.62% | — | 3.3 | When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply … | Mar 16, 2026 |
| CVE-2026-4224 | HIGH | 7.5 | 0.62% | — | 3.5 | When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply … | Mar 16, 2026 |
| CVE-2026-4224 | HIGH | 7.5 | 0.62% | — | 3.6 | When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply … | Mar 16, 2026 |
| CVE-2026-4224 | HIGH | 7.5 | 0.62% | — | 3.13 | When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply … | Mar 16, 2026 |
| CVE-2026-4224 | HIGH | 7.5 | 0.62% | — | 3.10 | When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply … | Mar 16, 2026 |
| CVE-2026-4224 | HIGH | 7.5 | 0.62% | — | 3.14 | When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply … | Mar 16, 2026 |
| CVE-2026-4224 | HIGH | 7.5 | 0.62% | — | 3.0 | When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply … | Mar 16, 2026 |
| CVE-2026-4224 | HIGH | 7.5 | 0.62% | — | 3.4 | When an Expat parser with a registered ElementDeclHandler parses an inline document type definition containing a deeply … | Mar 16, 2026 |
| CVE-2026-3644 | HIGH | 7.5 | 0.42% | — | 3.2 | The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()… | Mar 16, 2026 |
| CVE-2026-3644 | HIGH | 7.5 | 0.42% | — | 3.6 | The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()… | Mar 16, 2026 |
| CVE-2026-3644 | HIGH | 7.5 | 0.42% | — | 3.13 | The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()… | Mar 16, 2026 |
| CVE-2026-3644 | HIGH | 7.5 | 0.42% | — | 3.9 | The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()… | Mar 16, 2026 |
| CVE-2026-3644 | HIGH | 7.5 | 0.42% | — | 3.4 | The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()… | Mar 16, 2026 |
| CVE-2026-3644 | HIGH | 7.5 | 0.42% | — | 3.0 | The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()… | Mar 16, 2026 |
| CVE-2026-3644 | HIGH | 7.5 | 0.42% | — | 3.1 | The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()… | Mar 16, 2026 |
| CVE-2026-3644 | HIGH | 7.5 | 0.42% | — | 3.5 | The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()… | Mar 16, 2026 |
| CVE-2026-3644 | HIGH | 7.5 | 0.42% | — | 3.8 | The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()… | Mar 16, 2026 |
| CVE-2026-3644 | HIGH | 7.5 | 0.42% | — | 3.7 | The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()… | Mar 16, 2026 |
| CVE-2026-3644 | HIGH | 7.5 | 0.42% | — | 3.12 | The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()… | Mar 16, 2026 |
| CVE-2026-3644 | HIGH | 7.5 | 0.42% | — | 3.3 | The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()… | Mar 16, 2026 |
| CVE-2026-3644 | HIGH | 7.5 | 0.42% | — | 3.10 | The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()… | Mar 16, 2026 |
| CVE-2026-3644 | HIGH | 7.5 | 0.42% | — | 3.11 | The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()… | Mar 16, 2026 |
| CVE-2026-3644 | HIGH | 7.5 | 0.42% | — | 3.14 | The fix for CVE-2026-0672, which rejected control characters in http.cookies.Morsel, was incomplete. The Morsel.update()… | Mar 16, 2026 |
| CVE-2025-13462 | CRITICAL | 9.8 | 0.16% | — | 3.4 | The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi… | Mar 12, 2026 |
| CVE-2025-13462 | CRITICAL | 9.8 | 0.16% | — | 3.11 | The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi… | Mar 12, 2026 |
| CVE-2025-13462 | CRITICAL | 9.8 | 0.16% | — | 3.12 | The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi… | Mar 12, 2026 |
| CVE-2025-13462 | CRITICAL | 9.8 | 0.16% | — | 3.2 | The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi… | Mar 12, 2026 |
| CVE-2025-13462 | CRITICAL | 9.8 | 0.16% | — | 3.10 | The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi… | Mar 12, 2026 |
| CVE-2025-13462 | CRITICAL | 9.8 | 0.16% | — | 3.9 | The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi… | Mar 12, 2026 |
| CVE-2025-13462 | CRITICAL | 9.8 | 0.16% | — | 3.13 | The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi… | Mar 12, 2026 |
| CVE-2025-13462 | CRITICAL | 9.8 | 0.16% | — | 3.6 | The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi… | Mar 12, 2026 |
| CVE-2025-13462 | CRITICAL | 9.8 | 0.16% | — | 3.5 | The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi… | Mar 12, 2026 |
| CVE-2025-13462 | CRITICAL | 9.8 | 0.16% | — | 3.7 | The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi… | Mar 12, 2026 |
| CVE-2025-13462 | CRITICAL | 9.8 | 0.16% | — | 3.0 | The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi… | Mar 12, 2026 |
| CVE-2025-13462 | CRITICAL | 9.8 | 0.16% | — | 3.3 | The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi… | Mar 12, 2026 |
| CVE-2025-13462 | CRITICAL | 9.8 | 0.16% | — | 3.8 | The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi… | Mar 12, 2026 |
| CVE-2025-13462 | CRITICAL | 9.8 | 0.16% | — | 3.1 | The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi… | Mar 12, 2026 |
| CVE-2025-13462 | CRITICAL | 9.8 | 0.16% | — | 3.14 | The "tarfile" module would still apply normalization of AREGTYPE (\x00) blocks to DIRTYPE, even while processing a multi… | Mar 12, 2026 |
| CVE-2025-12781 | MEDIUM | 5.3 | 0.51% | — | 3.2 | When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the… | Jan 21, 2026 |
| CVE-2025-12781 | MEDIUM | 5.3 | 0.51% | — | 3.1 | When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the… | Jan 21, 2026 |
| CVE-2025-12781 | MEDIUM | 5.3 | 0.51% | — | 3.4 | When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the… | Jan 21, 2026 |
| CVE-2025-12781 | MEDIUM | 5.3 | 0.51% | — | 3.5 | When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the… | Jan 21, 2026 |
| CVE-2025-12781 | MEDIUM | 5.3 | 0.51% | — | 3.8 | When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the… | Jan 21, 2026 |
| CVE-2025-12781 | MEDIUM | 5.3 | 0.51% | — | 3.10 | When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the… | Jan 21, 2026 |
| CVE-2025-12781 | MEDIUM | 5.3 | 0.51% | — | 3.3 | When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the… | Jan 21, 2026 |
| CVE-2025-12781 | MEDIUM | 5.3 | 0.51% | — | 3.13 | When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the… | Jan 21, 2026 |
| CVE-2025-12781 | MEDIUM | 5.3 | 0.51% | — | 3.6 | When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the… | Jan 21, 2026 |
| CVE-2025-12781 | MEDIUM | 5.3 | 0.51% | — | 3.11 | When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the… | Jan 21, 2026 |
| CVE-2025-12781 | MEDIUM | 5.3 | 0.51% | — | 3.12 | When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the… | Jan 21, 2026 |
| CVE-2025-12781 | MEDIUM | 5.3 | 0.51% | — | 3.14 | When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the… | Jan 21, 2026 |
| CVE-2025-12781 | MEDIUM | 5.3 | 0.51% | — | 3.7 | When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the… | Jan 21, 2026 |
| CVE-2025-12781 | MEDIUM | 5.3 | 0.51% | — | 3.0 | When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the… | Jan 21, 2026 |
| CVE-2025-12781 | MEDIUM | 5.3 | 0.51% | — | 3.9 | When passing data to the b64decode(), standard_b64decode(), and urlsafe_b64decode() functions in the "base64" module the… | Jan 21, 2026 |
| CVE-2025-13836 | HIGH | 7.5 | 1.52% | — | 3.12 | When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content… | Dec 1, 2025 |
| CVE-2025-13836 | HIGH | 7.5 | 1.52% | — | 3.6 | When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content… | Dec 1, 2025 |
| CVE-2025-13836 | HIGH | 7.5 | 1.52% | — | 3.13 | When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content… | Dec 1, 2025 |
| CVE-2025-13836 | HIGH | 7.5 | 1.52% | — | 3.3 | When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content… | Dec 1, 2025 |
| CVE-2025-13836 | HIGH | 7.5 | 1.52% | — | 3.5 | When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content… | Dec 1, 2025 |
| CVE-2025-13836 | HIGH | 7.5 | 1.52% | — | 3.10 | When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content… | Dec 1, 2025 |
| CVE-2025-13836 | HIGH | 7.5 | 1.52% | — | 3.8 | When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content… | Dec 1, 2025 |
| CVE-2025-13836 | HIGH | 7.5 | 1.52% | — | 3.14 | When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content… | Dec 1, 2025 |
| CVE-2025-13836 | HIGH | 7.5 | 1.52% | — | 3.11 | When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content… | Dec 1, 2025 |
| CVE-2025-13836 | HIGH | 7.5 | 1.52% | — | 3.7 | When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content… | Dec 1, 2025 |
| CVE-2025-13836 | HIGH | 7.5 | 1.52% | — | 3.0 | When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content… | Dec 1, 2025 |
| CVE-2025-13836 | HIGH | 7.5 | 1.52% | — | 3.1 | When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content… | Dec 1, 2025 |
| CVE-2025-13836 | HIGH | 7.5 | 1.52% | — | 3.9 | When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content… | Dec 1, 2025 |
| CVE-2025-13836 | HIGH | 7.5 | 1.52% | — | 3.4 | When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content… | Dec 1, 2025 |
| CVE-2025-13836 | HIGH | 7.5 | 1.52% | — | 3.2 | When reading an HTTP response from a server, if no read amount is specified, the default behavior will be to use Content… | Dec 1, 2025 |
| CVE-2018-25032 | HIGH | 7.5 | 50.84% | — | 3.7 | zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matche… | Mar 25, 2022 |
| CVE-2018-25032 | HIGH | 7.5 | 50.84% | — | 3.10 | zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matche… | Mar 25, 2022 |
| CVE-2018-25032 | HIGH | 7.5 | 50.84% | — | 3.8 | zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matche… | Mar 25, 2022 |
| CVE-2018-25032 | HIGH | 7.5 | 50.84% | — | 3.9 | zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matche… | Mar 25, 2022 |
| CVE-2016-2183 | HIGH | 7.5 | 95.71% | — | 3.4 | The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a bi… | Sep 1, 2016 |
| CVE-2016-2183 | HIGH | 7.5 | 95.71% | — | 3.5 | The DES and Triple DES ciphers, as used in the TLS, SSH, and IPSec protocols and other protocols and products, have a bi… | Sep 1, 2016 |
Frequently asked questions
Is Python 3 end of life?
Partially. Some Python 3.x releases have reached EOL. Check the version table above for the exact status of each sub-release.
What CVEs affect Python 3?
There are 156 CVEs tracked for Python 3.x, including 30 critical severity issues. See the full list above with CVSS and EPSS scores.
What is the latest Python 3 version?
The latest Python 3.x patch release is 3.14.6, released on June 10, 2026. Always run the latest patch to benefit from all security fixes.
When was Python 3 first released?
Python 3.0 was initially released on October 7, 2025. See the full version timeline in the table above.
Is it safe to run Python 3 in production?
Python 3 is still supported and safe for production use until October 31, 2030. Ensure you are running the latest patch version (3.14.6) to have all security fixes applied.
Data sourced from endoflife.date · CVE data from NVD · EPSS from FIRST.org · KEV from CISA
