Python 3.12.13, 3.11.15 and 3.10.20 were released on March 3, 2026 as security updates for the Python 3.12, 3.11 and 3.10 branches. The releases address problems involving unsafe headers and control characters, XML and HTML processing, denial-of-service behavior, and memory safety.
These versions matter to teams still operating the affected branches, but they should be treated as a historical release point rather than the current target. Later official release pages show that Python 3.12.14, 3.11.16 and 3.10.21 superseded the versions announced in March.
What changed in the March releases
The Python project characterized all three releases as security releases. The corresponding Python 3.12.13, Python 3.11.15 and Python 3.10.20 pages document the changes for each branch.
Among the documented areas were:
- Unsafe email header folding and serialization behavior.
- Complexity issues involving legacy HTTP parameters.
- Control-character handling in WSGI headers, cookies and data URL media types.
- XML processing protections, including defenses against memory amplification.
- Denial-of-service behavior and quadratic-or-worse input processing.
- Hostile HTML and related markup handling.
- An SSL use-after-free affecting memory safety.
The releases also upgraded the bundled libexpat library to version 2.7.4. The announcement and release pages identify CVE-2026-24515, CVE-2026-25210 and mitigation for CVE-2025-59375 among the addressed issues. They also identify CVE-2024-6923 in the documented security work.
Python 3.11.15 and 3.10.20 additionally included fixes for specially crafted concurrent list rich-comparison inputs and list slice assignment. The announcement states that these fixes had already appeared in an earlier Python 3.12 release.
Who is affected
The relevant population is any system running Python 3.10, 3.11 or 3.12, particularly applications that process untrusted or externally supplied email, HTTP, cookie, URL, XML, HTML, archive or configuration data. Applications using SSL connections should also be reviewed because the release notes document an SSL memory-safety fix.
The practical effect is not limited to a version number. Several changes tighten input validation. Headers or control characters that were previously accepted may now be rejected. XML parser objects also gain allocation-tracker protections intended to limit memory amplification. Applications that depend on permissive parsing should therefore be tested for changed behavior.
The available sources do not establish that any particular application is exploitable, that the issues are being actively exploited, or that upgrading eliminates all security risk. They also do not provide application-specific compatibility results.
Source-only distribution changes the upgrade process
Python 3.10, 3.11 and 3.12 were in the security-fixes-only stage of their lifecycles when these releases were published. In this stage, the branches receive irregular source-only releases and do not receive new binary installers from the Python project.
The official pages provide source artifacts, including XZ-compressed and gzip-compressed tarballs for Python 3.11.15 and 3.10.20, together with Sigstore, GPG and SHA-256 verification references. The Python 3.12.13 page provides equivalent source-artifact and verification information.
This does not establish how a particular Linux distribution, operating system or package manager distributes the releases. Availability through downstream vendors may vary, and the supplied documentation does not provide deployment-specific installation commands or build procedures.
The announced versions are no longer the latest
Because the March announcement is now superseded, teams should not automatically select 3.12.13, 3.11.15 or 3.10.20 for a new remediation effort. The official release records show:
- Python 3.12.13 was superseded by Python 3.12.14.
- Python 3.11.15 was superseded by Python 3.11.16.
- Python 3.10.20 was superseded by Python 3.10.21.
The March versions remain important when auditing historical exposure or explaining changes in an existing build, but administrators should consult the latest release in the applicable branch. The Python Developer’s Guide version-status page lists the planned end-of-life dates for these security-stage branches as October 2026 for Python 3.10, October 2027 for Python 3.11 and October 2028 for Python 3.12.
What you should do
- Inventory affected runtimes. Identify systems and services still using Python 3.10, 3.11 or 3.12, including runtimes embedded in build, automation and administrative environments.
- Use the latest applicable branch release. Treat the March versions as the announced release point, not as the current latest versions. Check the official Python release pages for the superseding 3.12.14, 3.11.16 or 3.10.21 versions.
- Review input-processing paths. Pay particular attention to email headers, HTTP parameters, WSGI headers, cookies, URLs, XML, HTML, configuration files and SSL connections.
- Test stricter validation. Malformed or previously accepted input may now be rejected. Include negative-input and parser-behavior tests where those changes could affect application behavior.
- Validate source artifacts. If your organization obtains Python from source, use the official signature, Sigstore and SHA-256 references according to your established release-validation process.
- Check downstream packaging separately. The Python project’s source-only status does not document availability from a specific operating-system vendor or package manager, so confirm that status through the relevant downstream channel.
The release pages do not provide universal upgrade commands or organization-specific deployment instructions. Teams should apply their existing build, testing and rollout procedures rather than assuming that a particular package-manager workflow is supported by the Python project documentation cited here.
Availability and security context
Python 3.12.13, 3.11.15 and 3.10.20 were available from the Python project on March 3, 2026. Their security-stage lifecycle explains both the irregular release cadence and the absence of new binary installers. The documented fixes cover multiple input-processing and memory-safety areas, but the available material does not assign a complete severity or exploitability assessment to every issue.
For teams maintaining older Python services, the key distinction is between confirming historical exposure and choosing a current remediation target. The March releases provide the relevant security changes for that point in time; the later superseding releases are the versions administrators should investigate for current branch-level maintenance.
Sources
- Python Insider: Python 3.12.13, 3.11.15 and 3.10.20
- Python 3.12.13 release page
- Python 3.11.15 release page
- Python 3.10.20 release page
- Python Developer’s Guide: Status of Python versions
- Python 3.12.13 release page, including superseding-release information
- Python 3.11.16 release page
- Python 3.10.21 release page



