Skip to content

Commit acb4dc1

Browse files
committed
Python 3.10.22
1 parent 5867d4e commit acb4dc1

22 files changed

Lines changed: 181 additions & 70 deletions

‎Doc/library/asyncio-eventloop.rst‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -505,7 +505,7 @@ Opening network connections
505505

506506
For more information: https://tools.ietf.org/html/rfc6555
507507

508-
.. versionchanged:: next
508+
.. versionchanged:: 3.10.22
509509
Raises a ``DeprecationWarning`` if ``ssl.check_hostname`` is ``True``
510510
and ``server_hostname`` is not supplied. In Python 3.13 and
511511
later a ``ValueError`` is raised instead.

‎Doc/library/ssl.rst‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -1779,7 +1779,7 @@ to speed up repeated connections from the same clients.
17791779

17801780
.. versionadded:: 3.7
17811781

1782-
.. versionchanged:: next
1782+
.. versionchanged:: 3.10.22
17831783
After the callback assigns a new :attr:`SSLSocket.context`, later
17841784
ClientHello messages on the connection are dispatched to the new
17851785
context's *sni_callback*.
@@ -1914,7 +1914,7 @@ to speed up repeated connections from the same clients.
19141914
The method returns on instance of :attr:`SSLContext.sslobject_class`
19151915
instead of hard-coded :class:`SSLObject`.
19161916

1917-
.. versionchanged:: next
1917+
.. versionchanged:: 3.10.22
19181918
The *server_side*, *server_hostname* and *session* parameters are now
19191919
validated as :meth:`SSLContext.wrap_socket` validates them. Previously
19201920
a context with :attr:`~SSLContext.check_hostname` enabled and no

‎Doc/library/tarfile.rst‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -962,7 +962,7 @@ reused in custom filters:
962962

963963
Return the modified ``TarInfo`` member.
964964

965-
.. versionchanged:: next
965+
.. versionchanged:: 3.10.22
966966

967967
Filenames containing ``..`` components are now normalized.
968968

‎Doc/library/urllib.request.rst‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -927,7 +927,7 @@ These methods are available on :class:`HTTPPasswordMgr` and
927927
match authentication URIs with the same scheme or no scheme. A URI without a
928928
scheme matches authentication URIs with any scheme.
929929

930-
.. versionchanged:: next
930+
.. versionchanged:: 3.10.22
931931
Authentication credentials for URIs with a scheme are now scoped by
932932
that scheme.
933933

‎Include/patchlevel.h‎

Lines changed: 2 additions & 2 deletions
Original file line numberDiff line numberDiff line change
@@ -18,12 +18,12 @@
1818
/*--start constants--*/
1919
#define PY_MAJOR_VERSION 3
2020
#define PY_MINOR_VERSION 10
21-
#define PY_MICRO_VERSION 21
21+
#define PY_MICRO_VERSION 22
2222
#define PY_RELEASE_LEVEL PY_RELEASE_LEVEL_FINAL
2323
#define PY_RELEASE_SERIAL 0
2424

2525
/* Version as a string */
26-
#define PY_VERSION "3.10.21+"
26+
#define PY_VERSION "3.10.22"
2727
/*--end constants--*/
2828

2929
/* Version as a single 4-byte hex number, e.g. 0x010502B2 == 1.5.2b2.

‎Lib/pydoc_data/topics.py‎

Lines changed: 1 addition & 1 deletion
Original file line numberDiff line numberDiff line change
@@ -1,5 +1,5 @@
11
# -*- coding: utf-8 -*-
2-
# Autogenerated by Sphinx on Thu Aug 13 00:02:25 2026
2+
# Autogenerated by Sphinx on Thu Oct 1 01:47:59 2026
33
topics = {'assert': 'The "assert" statement\n'
44
'**********************\n'
55
'\n'

‎Misc/NEWS.d/3.10.22.rst‎

Lines changed: 171 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -0,0 +1,171 @@
1+
.. date: 2026-09-29-16-32-46
2+
.. gh-issue: 158446
3+
.. nonce: dToaPr
4+
.. release date: 2026-10-01
5+
.. section: Security
6+
7+
Fix a crash or incorrect output that could occur when formatting a
8+
:class:`float` or :class:`complex` with a precision close to the platform's
9+
``INT_MAX``. :c:func:`PyOS_double_to_string` now raises :exc:`ValueError`
10+
for any precision of that magnitude, regardless of presentation type or
11+
value, as the format string parsers already did for precisions above
12+
``INT_MAX``.
13+
14+
..
15+
16+
.. date: 2026-09-23-11-34-30
17+
.. gh-issue: 156793
18+
.. nonce: zC_AjF
19+
.. section: Security
20+
21+
:mod:`asyncio`: :meth:`loop.start_tls() <asyncio.loop.start_tls>` and
22+
:meth:`loop.create_connection() <asyncio.loop.create_connection>` now
23+
validate the *server_hostname* argument if an :class:`ssl.SSLContext` is
24+
passed with *check_hostname* set to ``True``, emitting
25+
:exc:`DeprecationWarning` if *server_hostname* is missing. (This will raise
26+
:exc:`ValueError` in Python 3.13 and later.)
27+
28+
..
29+
30+
.. date: 2026-09-16-14-05-19
31+
.. gh-issue: 156793
32+
.. nonce: Qa1T5Z
33+
.. section: Security
34+
35+
:meth:`ssl.SSLContext.wrap_bio` now validates its *server_side*,
36+
*server_hostname* and *session* arguments similar to
37+
:meth:`ssl.SSLContext.wrap_socket`, but for backward compatiblity reasons
38+
emits :exc:`DeprecationWarning` instead of :exc:`ValueError`.
39+
40+
In particular, a context with :attr:`~ssl.SSLContext.check_hostname` enabled
41+
and no *server_hostname* passed to :meth:`!wrap_bio` now emits
42+
:exc:`DeprecationWarning` to indicate the hostname wasn't checked. (In
43+
Python 3.13 and later, this raises :exc:`ValueError`.)
44+
45+
..
46+
47+
.. date: 2026-09-10-13-38-11
48+
.. gh-issue: 157265
49+
.. nonce: -vYuMp
50+
.. section: Security
51+
52+
In :mod:`tarfile`, when extracting a link falls back to extracting a member
53+
of the archive, skip the member when the filter function returns None when
54+
called with the extracted member's name replaced with the link's.
55+
56+
..
57+
58+
.. date: 2026-09-06-11-02-46
59+
.. gh-issue: 157190
60+
.. nonce: tarhln
61+
.. section: Security
62+
63+
Fixed a vulnerability in the :mod:`tarfile` ``data`` and ``tar`` extraction
64+
filters where a crafted archive using a hard link to a symbolic link could
65+
change the permissions and modification time of a file outside the
66+
destination directory, and expose its contents inside the extracted tree.
67+
This addresses CVE 2026-82049.
68+
69+
..
70+
71+
.. date: 2026-08-31-16-47-33
72+
.. gh-issue: 157953
73+
.. nonce: KxCF5N
74+
.. section: Security
75+
76+
Update bundled `libexpat <https://libexpat.github.io/>`_ to version 2.8.5.
77+
78+
..
79+
80+
.. date: 2026-08-18-13-54-05
81+
.. gh-issue: 156002
82+
.. nonce: CcWXPP
83+
.. section: Security
84+
85+
Bound the amount of data :mod:`zipfile` decompresses per read for members
86+
compressed with bzip2, LZMA, or Zstandard, matching the existing limit for
87+
deflate. A small archive member could previously expand into an unbounded
88+
allocation even when read in small chunks.
89+
90+
..
91+
92+
.. date: 2026-08-13-13-08-11
93+
.. gh-issue: 155999
94+
.. nonce: Xt4rWq
95+
.. section: Security
96+
97+
Fix the :mod:`tarfile` ``tar`` and ``data`` extraction filters creating
98+
directories outside the destination for members whose name leaves the
99+
destination and returns to it, such as ``../evil/../dest/sub/file``. The
100+
containment check used the resolved path, but intermediate directories were
101+
created from the name as given.
102+
103+
..
104+
105+
.. date: 2026-08-10-12-00-00
106+
.. gh-issue: 156293
107+
.. nonce: sNIcbk
108+
.. section: Security
109+
110+
Fix a crash in :mod:`ssl` when an :attr:`~ssl.SSLContext.sni_callback`
111+
switches a connection to another :class:`~ssl.SSLContext` and the context
112+
that carries the callback is no longer referenced by the application.
113+
Servers that keep their ``sni_callback`` context alive (the usual case when
114+
it wraps the listening socket or is stored on the server object) were not
115+
affected. This addresses `CVE-2026-19445
116+
<https://www.cve.org/CVERecord?id=CVE-2026-19445>`_.
117+
118+
..
119+
120+
.. date: 2026-08-06-11-43-20
121+
.. gh-issue: 155292
122+
.. nonce: j4pHBO
123+
.. section: Security
124+
125+
Change the :mod:`stringprep` module and :mod:`encodings.idna` codec to not
126+
consider Unicode codepoint attributes beyond those defined in :rfc:`3454`.
127+
128+
..
129+
130+
.. date: 2026-07-31-16-20-17
131+
.. gh-issue: 155694
132+
.. nonce: SsxlKG
133+
.. section: Security
134+
135+
Fix `CVE-2026-15806 <https://www.cve.org/CVERecord?id=CVE-2026-15806>`_ by
136+
scoping :class:`~urllib.request.HTTPPasswordMgr` credentials to the URL
137+
scheme, preventing credentials stored for an HTTPS URL from being used for a
138+
matching HTTP URL, while URIs without a scheme continue to match any scheme.
139+
140+
..
141+
142+
.. date: 2026-04-26-19-30-45
143+
.. gh-issue: 149018
144+
.. nonce: a9SqWb
145+
.. section: Security
146+
147+
Improved protection against XML hash-flooding attacks in
148+
:mod:`xml.parsers.expat` and :mod:`xml.etree.ElementTree` when Python is
149+
compiled with libExpat 2.8.0 or later.
150+
151+
..
152+
153+
.. date: 2026-09-08-13-06-29
154+
.. gh-issue: 156002
155+
.. nonce: vmOC8T
156+
.. section: Library
157+
158+
:mod:`zipfile` again reads members through a third-party decompressor
159+
installed by monkey-patching the private ``_get_decompressor()`` to return
160+
an object that only implements old BZ2Decompressor API from Python 3.3. Note
161+
that decompressors without ``needs_input`` and two-argument ``decompress()``
162+
are vulnerable to CVE 2026-15310.
163+
164+
..
165+
166+
.. date: 2026-08-26-02-30-00
167+
.. gh-issue: 156353
168+
.. nonce: abcdef
169+
.. section: Library
170+
171+
Fix :mod:`configparser` parsing when using whitespace in *delimiters*.

‎Misc/NEWS.d/next/Library/2026-08-26-02-30-00.gh-issue-156353.abcdef.rst‎

Lines changed: 0 additions & 1 deletion
This file was deleted.

‎Misc/NEWS.d/next/Library/2026-09-08-13-06-29.gh-issue-156002.vmOC8T.rst‎

Lines changed: 0 additions & 5 deletions
This file was deleted.

‎Misc/NEWS.d/next/Security/2026-04-26-19-30-45.gh-issue-149018.a9SqWb.rst‎

Lines changed: 0 additions & 3 deletions
This file was deleted.

0 commit comments

Comments
 (0)