Python 3.12.14
Release date: August 12, 2026
Security content in this release
- gh-155558: Update bundled libexpat to version 2.8.3 for the fix to CVE 2026-72522.
- gh-153030: Fixed quadratic complexity in incremental parsing of long unterminated constructs (such as tags or comments) in
html.parser.HTMLParser, which could be exploited for a denial of service. - gh-152674: The
xml.etree.ElementTree.Elementmethodsfindall(),iterfind()andfind()avoid quadratic behavior when using XPath index predicates ([1],[last()],[last()-N]) on XML documents with many same-tag siblings. - gh-152216: Update bundled libexpat to version 2.8.2.
- gh-151987: The
tarfile.TarFile.extract()method now applies the given filter when it extracts a link target from the archive as a fallback. - gh-151981: In
tarfile, seeking a stream now stops when end of the stream is reached. - gh-151544:
Modules/Setup.localis no longer used as a landmark to discover whether Python is running in a source tree, as it could potentially affect actual installs. Thepybuilddir.txtfile is now the sole indicator of running in a source tree. - gh-151558: Fixed an vulnerability in the
tarfiledataandtarextraction filters where crafted archives could create a symlink pointing outside the destination directory. This was a bypass of CVE 2025-4330. - gh-150599: Fix a possible stack buffer overflow in
bz2when abz2.BZ2Decompressoris reused after a decompression error. The decompressor now becomes unusable after libbz2 reports an error. - gh-150743:
http.clientnow limits the number of chunked-response trailer lines it will read to 100, and the number of interim (1xx) responses it will skip to 100. A malicious or broken server could previously stream trailer lines or100 Continueresponses forever, hanging the client even when a socket timeout was in use. Reported by@YLChen-007via GHSA-w4q2-g22w-6fr4. - gh-149698: Update bundled libexpat to version 2.8.1 for the fix for CVE 2026-45186.
- gh-87451: The
ftplibmodule’s undocumentedftpcpfunction no longer trusts the IPv4 address value returned from the source server in response to thePASVcommand by default, completing the fix for CVE-2021-4189. As withftplib.FTP, the former behavior can be re-enabled by setting thetrust_server_pasv_ipv4_addressattribute on the sourceftplib.FTPinstance toTrue. Thanks to Qi Deng at Aurascape AI for the report. - gh-149486:
tarfile.data_filter()now validates link targets using the same normalised value that is written to disk, strips trailing separators from the member name when resolving a symlink’s directory, and rejects link members that would replace the destination directory itself. This closes several path-traversal bypasses of thedataextraction filter. - gh-149079: Fix a potential denial of service in
unicodedata.normalize(). The canonical ordering step of Unicode normalization used a quadratic-time insertion sort for reordering combining characters, which could be exploited with crafted input containing many combining characters in non-canonical order. Replaced with a linear-time counting sort for long runs. - gh-149018: Improved protection against XML hash-flooding attacks in
xml.parsers.expatandxml.etree.ElementTreewhen Python is compiled with libExpat 2.8.0 or later. - gh-149017: Update bundled libexpat to version 2.8.0.
- gh-148808: Added buffer boundary check when using
nbytesparameter withasyncio.AbstractEventLoop.sock_recvfrom_into(). Only relevant for Windows and theasyncio.ProactorEventLoop. - gh-148395: Fix a dangling input pointer in
lzma.LZMADecompressor,bz2.BZ2Decompressor, and internalzlib._ZlibDecompressorwhen memory allocation fails withMemoryError, which could let a subsequentdecompress()call read or write through a stale pointer to the already-released caller buffer. - gh-148169: A bypass in
webbrowserallowed URLs prefixed with%actionto pass the dash-prefix safety check. - gh-146581: Fix vulnerability in
shutil.unpack_archive()for ZIP files on Windows which allowed to write files outside of the destination tree if the patch in the archive contains a Windows drive prefix. Now such invalid paths will be skipped. Files containing “..” in the name (like “foo..bar”) are no longer skipped. - gh-146333: Fix quadratic backtracking in
configparser.RawConfigParseroption parsing regexes (OPTCREandOPTCRE_NV). A crafted configuration line with many whitespace characters could cause excessive CPU usage. - gh-146211: Reject CR/LF characters in tunnel request headers for the HTTPConnection.set_tunnel() method.
- gh-145986:
xml.parsers.expat: Fixed a crash caused by unbounded C recursion when converting deeply nested XML content models withElementDeclHandler(). This addresses CVE 2026-4224. - gh-145599: Reject control characters in
http.cookies.Morselupdate()andjs_output(). This addresses CVE 2026-3644. - gh-145506: Fixes CVE 2026-2297 by ensuring that
SourcelessFileLoaderusesio.open_code()when opening.pycfiles. - gh-144370: Disallow usage of control characters in status in
wsgiref.handlersto prevent HTTP header injections. Patch by Benedikt Johannes. - gh-143930: Reject leading dashes in URLs passed to
webbrowser.open(). - gh-143927: Normalize all line endings (CR, CRLF, and LF) to LF+TAB when writing multi-line configparser values.
Files
| Version | Description | File Size |
|---|---|---|
| Windows installer (64-bit) | Recommended | 25.6 MB |
| Windows installer (32-bit) | 24.4 MB | |
| Windows installer (ARM64) | Experimental | 24.9 MB |