Python 3.10.22 marks end of life as core team ships a full release sweep
Python 3.10 has gone end of life, and the same October 1 drop also shipped 3.11.17, 3.12.15, 3.13.16, and 3.14.8.
The Python core team just cut five versions in a single coordinated drop on October 1, 2026, and one of them ends a five-year era. Python 3.10.22 is the final release of the 3.10 series, which now goes end of life. No more security updates of any kind come after this. If you still run 3.10 anywhere in your stack, consider this your formal deadline.
The same announcement also shipped 3.11.17, 3.12.15, 3.13.16, and 3.14.8. All five are maintenance builds, meaning bug fixes and security patches only, no new features by design. That's the deal with point releases: they keep things from breaking. But this sweep carries extra weight because of what 3.10.22 represents.
What each release actually is
3.10.22 hits its PEP 619 finish line here. It's source-only, as it's been since 3.10.12, so there are no Windows or macOS installers to download. The last time you could grab a binary for 3.10 was back in April 2023.
3.11.17 follows the same security-fix-only pattern that began in April 2024. That line keeps churning out security releases until around October 2027.
3.12.15 is still actively supported, with full security coverage running until October 2028, though this build happens to be source-only. The series itself is in good shape.
3.13.16 earns a spot in the spotlight for one reason: it's the last "full" maintenance release of 3.13. After this, 3.13 will carry security fixes only. Unlike the three older lines, though, it does ship binary installers for Windows, macOS, and Android.
3.14.8 is the current feature series, so it still bundles new capabilities alongside fixes. Binary installers cover Windows, macOS, Android, and iOS, and it carries the most current bundled cryptography stack of the group.
So this coordinated drop lets everyone, whether you're on the ancient 3.10 line or the freshest 3.14, grab the latest patches at once.
Why 3.10's end of life actually matters
When a Python series reaches end of life, it stops getting every kind of update, security patches included. Any bug found in 3.10 after October 2026 stays unfixed in that line forever. For a solo developer, that's a gentle nudge to upgrade. For an enterprise running legacy systems on 3.10, it's a compliance problem that usually kicks off a migration project.
3.10 landed on October 4, 2021, so its five-year window closed cleanly with this final release. It was a popular, long-lived series that gave us union types as X | Y, structural pattern matching with match/case, explicit type aliases, and optional length-checking in zip(). Pattern matching, honestly, was the showpiece.
The release manager, Pablo Galindo Salgado, oversaw both the 3.10 and 3.11 lines, which is why his note reads more like a goodbye than a changelog.
The security fixes
Every one of the five bundles the same core set of fixes, with a few version-specific additions layered on top. The headline items span a few attack classes you'll recognize from the security news.
A crafted tar archive with a hard link pointing at a symlink could reach outside the extraction folder and touch files outside it. That's CVE-2026-82049. A sibling "leave and return" path-traversal hole (CVE-2026-19672) let names like ../evil/../dest/sub/file slip intermediate directories past the containment check. Both are now patched.
There's also a ZIP decompression bomb fix (CVE-2026-15310) that bounds how much data a single read will unpack, so a tiny bzip2 or LZMA member can't balloon into a memory-eating monster. An HTTPS credential leak (CVE-2026-15806) that let HTTPPasswordMgr reuse secure credentials over plain HTTP is sealed off too.
The TLS work (CVE-2026-19553) makes ssl.SSLContext.wrap_bio() validate its hostname the way wrap_socket() always has. On 3.13 and later, a missing hostname now raises a ValueError instead of just emitting a warning.
A handful of extras round it out. libexpat bumps to 2.8.5, 3.10.22 gets an XML hash-flooding hardening for completeness, and 3.13.16 and 3.14.8 jump OpenSSL to 3.5.9. Keep in mind that the source-only 3.10 through 3.12 releases don't bundle OpenSSL at all, so that only reaches the two newer lines.
A black hole opens and closes the loop
Here's where the story gets a bit charming. Python has a long-running tradition where each release note ends with an offbeat science aside, that "And now for something completely different" bit from Victor Borge. This October drop keeps the habit alive with a full-circle moment.
3.10 debuted in October 2021 with an essay on falling into a Schwarzschild black hole. Five years later, its final release closes with ringdown: the gravitational-wave buzz a merging black hole emits as it settles down. "We started Python 3.10 with a trip inside a Schwarzschild black hole," Salgado wrote, "so it seems only fair to finish with black holes as well."
It's a nice touch, for what it's worth. The people keeping the world's most-used languages running tend to be driven by the same curiosity that pulls them into astrophysics in the first place.
What you should do
The guidance from the release team is blunt. If you're still on 3.10, upgrade. Teams weighing timing have a decent spread to work with: 3.12 and 3.13 offer the longest remaining security windows, while 3.14 is the freshest but newest.
Salgado also leaves a door open. His note points out that 3.11 still has another year of security fixes ahead, so he'll likely be the release manager again when 3.11 eventually hits end of life in October 2027.
All five releases are available now. Head here to the download and here for the full changelogs.
