Python 3.12.14, 3.11.16 and 3.10.21 became available on August 12, 2026, giving teams security-focused updates for three maintained Python branches. The releases address issues in areas including archive extraction, URL handling, HTTP parsing, XML processing, decompression and denial-of-service protections.
The updates matter most to organizations running Python 3.10, 3.11 or 3.12 in applications that process untrusted files, network responses, configuration data or other external input. However, these are source-only releases, so deployment planning must account for an organization’s existing build and packaging process.
What changed in the new Python releases
The Python announcement lists all three versions as available. The official release pages identify Python 3.11.16 and Python 3.10.21 as security bugfix releases for their legacy branches. The supplied release information also identifies Python 3.12 as being in a security-fix-only stage.
The detailed security-content information available for Python 3.11.16 and Python 3.10.21 covers several standard-library components:
sslhandling for DER data with trailing content.webbrowserURL processing, including leading-dash and percent-action handling.tarfileextraction filters and path-traversal protections.- HTTP tunnel headers, response handling and control-character validation.
- FTP PASV address handling.
.pycloading and WSGI status validation.- XML parser recursion, hash-flooding protection and billion-laughs attack controls.
- Cookie processing, decompression and asynchronous buffer handling.
- Windows ZIP extraction paths.
- Parser-complexity and other denial-of-service protections.
The Python 3.11.16 release page states that its bundled libexpat version is updated to 2.8.3. It also documents improved XML hash-flooding protection when Python is compiled with libExpat 2.8.0 or later. Python 3.10.21 updates its bundled libexpat to 2.8.2, according to the Python 3.10.21 release page.
The verified release information does not provide a complete item-by-item account of every change in the supplied material, so the list above should be treated as a set of documented security-content highlights rather than an exhaustive transcription.
Source-only availability changes deployment planning
Python 3.10.21 and 3.11.16 are distributed as source releases. Their official pages provide XZ-compressed and gzipped source archives, signature links and SHA-256 checksums. Python 3.10, 3.11 and 3.12 are in security-fix-only stages, with irregular, as-needed releases and no binary installers.
For Python 3.11, version 3.11.9 was the last full bugfix release with binary installers. For Python 3.10, that milestone was 3.10.11. The Python 3.12.14 release page likewise does not provide binary installers.
This does not prescribe one universal installation method. The supplied sources do not document general system requirements, build dependencies, operating-system support matrices or complete installation commands. Teams should therefore use their established source-build, packaging and deployment procedures and verify the resulting artifacts before production rollout.
Lifecycle information is also branch-specific. Python 3.11 security-only releases are scheduled on an as-needed basis until October 2027, while Python 3.10 security-only releases are scheduled until October 2026. The Python Developer’s Guide version information, along with PEP 619 and PEP 664, provides the related maintenance-policy context.
Compatibility behavior to review
One behavior that may require focused testing affects ftplib. The releases change the handling of the address supplied by an FTP server in response to PASV. Applications that depend on the former trust behavior can re-enable it by setting trust_server_pasv_ipv4_address to True on the source ftplib.FTP instance.
That setting should not be changed automatically across every deployment. Administrators should first identify whether an application relies on the previous behavior and then test the connection path with the organization’s FTP infrastructure.
Other changes may affect how malformed or adversarial input is handled. Applications that consume archives, XML, HTTP responses, cookies, CSV data, TOML keys, compressed content or browser URLs should be tested against representative inputs after the runtime update. The supplied evidence does not establish that third-party packages require updates or that application-code changes will be necessary.
What you should do
- Inventory runtime branches. Determine whether production services, build systems, containers or scheduled jobs use Python 3.10, 3.11 or 3.12.
- Review the release notes. Pay particular attention to standard-library modules used to process untrusted archives, XML, HTTP traffic, FTP connections, compressed data, configuration files, cookies or browser URLs.
- Plan a source-based build. Obtain the matching release archive, verify its signature and SHA-256 checksum, and apply it through the organization’s tested build and packaging workflow.
- Test input-sensitive workloads. Check behavior for malformed archives, XML documents, HTTP responses, CSV and TOML input, cookies and compressed data. The new protections may bound, reject or otherwise process problematic input differently.
- Check FTP compatibility. Review any use of
ftplibPASV connections and thetrust_server_pasv_ipv4_addressattribute before upgrading. - Validate deployment artifacts. Because these branches no longer provide binary installers, confirm that internal packages and runtime images are built successfully for each supported environment.
Security and release caveats
These releases are explicitly characterized as security releases, and their documented changes include protections for archive path traversal, unsafe URL processing, HTTP control characters, parser recursion and complexity, XML processing, decompression and other denial-of-service conditions.
The release pages identify fixes associated with several CVE records, including CVE-2021-4189, CVE-2026-2297, CVE-2026-4224 and CVE-2026-3644. The supplied release information does not independently establish severity ratings, exploitability, active exploitation or affected-version ranges beyond the release-specific documentation. Those details should not be inferred from the version announcement.
Python 3.12.14, 3.11.16 and 3.10.21 are available now, but the exact upgrade procedure depends on the build and deployment environment. Organizations without an established source-build and packaging workflow may need to account for additional operational work before adopting the updates.



