Python published security releases for four branches on October 9, 2025: Python 3.12.12, 3.11.14, 3.10.19 and 3.9.24. The updates focus on bundled libexpat, XML parser lifetime handling, archive validation and HTML parsing. Several branches also receive packaging or SSL-related changes.
For maintainers, the release announcement is important for two reasons. First, these are security releases rather than feature updates, so environments on the affected branches should be reviewed for the documented fixes. Second, the packages are source-only: the official release pages do not provide binary installers, which may require changes to build and deployment processes.
What changed in the four Python releases
All four versions update bundled libexpat to version 2.7.3 to address CVE-2025-59375. They also change xml.parsers.expat so that a parent Expat parser is garbage-collected only after it is no longer referenced by subparsers created through ExternalEntityParserCreate().
The releases also tighten archive validation. The documented changes cover non-negative member offsets in tarfile, consistency checks for the ZIP64 end-of-central-directory record, and supported ZIP64 extensible data when no bytes precede the ZIP file. Applications that process archives, especially input from outside a trusted workflow, should be tested against these changes rather than assuming malformed input will continue to be handled in the same way.
Another shared change affects html.parser.HTMLParser. Its behavior is brought into closer alignment with HTML5 in areas including start and end tags, CDATA, comments, raw-text elements and end-of-file handling. The parser also avoids quadratic complexity when processing specially crafted input. These changes may alter results for applications that intentionally accept malformed HTML or depend on older parser behavior.
The Python release announcement and the corresponding Python 3.12.12 release page document the shared changes.
Branch-specific updates
Python 3.11.14, 3.10.19 and 3.9.24 update bundled setuptools to version 79.0.1. The release notes associate that update with CVE-2025-47273 and CVE-2024-6345.
Python 3.9.24 also changes ssl.SSLContext.set_npn_protocols() so that an empty protocols argument raises ssl.SSLError. Teams maintaining Python 3.9 applications should check whether their code can pass an empty value to this method and test the resulting behavior before deploying the update.
The individual release pages provide the branch-specific details for Python 3.11.14, Python 3.10.19 and Python 3.9.24.
Source-only distribution changes the upgrade path
None of the four releases provides binary installers. The official pages list source tarballs, including XZ-compressed and gzip formats for Python 3.11.14, 3.10.19 and 3.9.24, together with signature or verification references. Python 3.12.12 is likewise identified as a source-only security release.
This means an organization that previously obtained Python through a binary installer cannot assume an equivalent installer is available for these exact versions. The documented requirement is a source-build workflow when a deployment needs these releases. The supplied release information does not specify operating-system, compiler, dependency or platform compatibility requirements, so those details must be evaluated within each organization’s existing build environment.
Source artifacts should be obtained through the official release pages, and teams should use the signature or verification references provided there. The release pages do not establish compatibility with particular third-party packages, operating systems or deployment platforms.
Lifecycle status matters as much as the patch level
These versions were available on October 9, 2025, but the official pages now indicate that the listed releases have been superseded. The original release date should therefore be distinguished from their current status.
Python 3.11 remains scheduled for source-only security releases through October 2027, while Python 3.10 is scheduled for source-only security releases through October 2026. Those timelines make 3.10 and 3.11 different from Python 3.9, whose security-only maintenance ended on October 31, 2025. Python 3.9.24 was followed by Python 3.9.25, identified as the final security release, and Python 3.9 reached end of life.
The lifecycle policies are documented in PEP 619 for Python 3.10 and 3.11 and PEP 596 for Python 3.9. Organizations still operating Python 3.9 should treat migration planning as a separate priority rather than treating 3.9.24 as a long-term maintenance destination.
What you should do
- Inventory affected runtimes. Identify local development environments, CI jobs, build images and production services using Python 3.12, 3.11, 3.10 or 3.9.
- Review the current official release status. Because the listed versions have since been superseded, use the relevant Python release page to determine the appropriate current replacement rather than stopping at the October 9 versions.
- Plan for source builds where necessary. The official pages do not provide binary installers for these releases. Confirm that build automation can obtain, verify and compile the required source artifacts.
- Test parser-sensitive workloads. Exercise code using
HTMLParser, archive readers, XML parsing and malformed or specially crafted input. Pay particular attention to the documented HTML5-alignment and archive-validation changes. - Check Python 3.9 SSL usage. Test any code that calls
ssl.SSLContext.set_npn_protocols()with a potentially empty argument, because Python 3.9.24 changes that case to raisessl.SSLError. - Use the official verification references. Retrieve source packages from the release pages and follow their listed signature or verification information before incorporating them into a build process.
The supplied release documentation does not establish the severity, exploitability or application-specific exposure of the cited CVEs. It also does not establish third-party package compatibility or a universal migration procedure. Teams should therefore validate their own workloads and deployment systems rather than assuming that every application will behave identically after the update.



