Python 3.14.2 and Python 3.13.11 were released on December 5, 2025 as expedited maintenance releases. Both address regressions and security issues, with the most consequential changes affecting multiprocessing upgrades, dictionary insertion behavior, regular-expression scanning, HTTP modules, and XML processing.
For teams maintaining Python 3.14 or 3.13 applications, these releases are worth reviewing as part of normal maintenance. However, the versions are no longer the latest maintenance releases: the official release pages now state that both have been superseded. Use the Python 3.14.2 release page and Python 3.13.11 release page for historical release details and available artifacts, while checking the current Python release situation before deploying.
What changed in Python 3.14.2 and 3.13.11
Python 3.14.2 is the second maintenance release in the Python 3.14 series. It contains 18 bug fixes, build improvements, and documentation changes since Python 3.14.1. Python 3.13.11 is the eleventh maintenance release in the Python 3.13 series.
The releases were expedited to address several regressions. These included problems involving multiprocessing during in-place upgrades, insertdict failures, and crashes in re.Scanner when patterns contain multiple capturing groups. The official announcement and release documentation describe overlapping fixes, but they do not establish that the two releases contain identical complete change sets.
Multiprocessing resource-tracker compatibility
Python 3.14.2 changes the multiprocessing resource tracker to use the original communication protocol by default, matching Python 3.14.0 and earlier. The tracker remains compatible with subprocesses using the newer protocol, including specified Python 3.13.10, 3.14.1, and 3.15 subprocesses.
This matters most to applications and deployment processes that perform in-place Python upgrades or coordinate work across Python subprocesses. The supplied documentation does not provide a formal migration procedure, so teams should treat this as an area for targeted application testing rather than assuming that every deployment will be affected.
Dataclasses and scanner regressions
Python 3.14.2 fixes dataclasses regressions involving dataclasses without an __init__ method and annotation-related behavior. It also reverts relevant undocumented re.Scanner changes.
Capturing groups remain allowed in re.Scanner for backward compatibility, but the changelog warns that they can produce incorrect results. It also says that capturing groups will be forbidden in future Python versions. Projects relying on this undocumented behavior should therefore review those patterns rather than treating the compatibility behavior as permanent.
HTTP and XML security-related fixes
Python 3.14.2 fixes quadratic behavior when the XML minidom node ID cache is cleared, an issue associated with CVE-2025-12084. It also addresses a potential virtual-memory allocation denial-of-service condition in http.server, including a Windows CGI-server scenario described in the official changelog.
Python 3.13.11 addresses CVE-2025-12084 and potential denial-of-service conditions in http.client and http.server. The supplied release information does not provide severity ratings, complete affected-version ranges, or exploit-status details for the HTTP issues. It also does not establish that every Python deployment is affected; relevance depends on the code paths and workloads in use.
Availability and release artifacts
The Python 3.14.2 release page lists source tarballs, macOS installers for macOS 10.15 and later, Windows 64-bit and 32-bit installers, experimental Windows ARM64 installers, Windows embeddable packages, and Android packages for aarch64 and x86_64.
Python 3.13.11 lists source tarballs, macOS installers for macOS 10.13 and later, Windows 64-bit and 32-bit installers, experimental Windows ARM64 installers, and Windows embeddable packages. These lists describe the artifacts published for the releases; they are not a complete platform-support matrix.
Both release pages provide artifact checksums and Sigstore metadata. The Python 3.13.11 page also lists GPG signatures. For Python 3.14.2, the release information states that Python 3.14 and later no longer provide PGP signatures and recommends Sigstore for verification.
For Windows, the official release information points users to the Python install manager. The release manifests include commands such as py install 3.14 and py install 3.13. The supplied sources do not document general installation procedures for other operating systems or package managers, and they do not establish when third-party distributions made these versions available.
What the releases mean for support planning
Python 3.13 is expected to receive regular bug-fix updates for approximately 24 months, followed by source-only security updates until approximately October 2029, according to PEP 719. Python 3.14 has a similar planned phase of regular bug-fix updates, followed by source-only security updates until approximately October 2030, as documented in PEP 745.
These schedules help teams distinguish a branch’s maintenance phase from its later source-only security phase. They do not amount to a universal recommendation to upgrade immediately, and they do not replace an application-specific compatibility assessment. Because 3.14.2 and 3.13.11 have since been superseded, deployment decisions should also account for newer maintenance releases.
What you should do
- Review the current release target. If you are evaluating Python 3.14.2 or 3.13.11 today, first account for the fact that both versions have been superseded. Use the official release pages to compare artifacts and release documentation.
- Test multiprocessing upgrade paths. Applications that use multiprocessing, especially those involved in in-place interpreter upgrades or mixed-version subprocess environments, should test process startup and resource-tracker behavior in a representative deployment.
- Inspect undocumented
re.Scannerusage. Search for scanner patterns containing capturing groups. The documented compatibility behavior can produce incorrect results, and future Python versions are expected to forbid those groups. - Exercise affected library paths. Include dataclasses, XML
minidom,http.client, andhttp.serverin regression testing where they are used. Services handling untrusted connections should give particular attention to the documented HTTP denial-of-service fixes without assuming that every service is affected. - Verify downloaded artifacts. Obtain installers or source archives from the official Python release pages and use the listed checksums and Sigstore metadata. For Python 3.13.11, the page also lists GPG signatures; Python 3.14.2 directs users toward Sigstore instead of PGP signatures.
- Plan around the branch lifecycle. Record the expected bug-fix and source-only security-support periods for the Python branch you operate, while treating the dates as lifecycle information rather than a blanket upgrade mandate.
The supplied release information does not establish mandatory migration prerequisites, rebuild requirements, compiler requirements, or special configuration changes. Teams should avoid assuming that an interpreter update alone proves application compatibility; targeted testing remains necessary for the affected code paths.



