https://github.com/python/cpython/commit/acb4dc12b6df8615af7b43120ef601e04072f7d2
commit: acb4dc12b6df8615af7b43120ef601e04072f7d2
branch: 3.10
author: Pablo Galindo Salgado <[email protected]>
committer: pablogsal <[email protected]>
date: 2026-10-01T01:48:01+01:00
summary:
Python 3.10.22
files:
A Misc/NEWS.d/3.10.22.rst
D Misc/NEWS.d/next/Library/2026-08-26-02-30-00.gh-issue-156353.abcdef.rst
D Misc/NEWS.d/next/Library/2026-09-08-13-06-29.gh-issue-156002.vmOC8T.rst
D Misc/NEWS.d/next/Security/2026-04-26-19-30-45.gh-issue-149018.a9SqWb.rst
D Misc/NEWS.d/next/Security/2026-07-31-16-20-17.gh-issue-155694.SsxlKG.rst
D Misc/NEWS.d/next/Security/2026-08-06-11-43-20.gh-issue-155292.j4pHBO.rst
D Misc/NEWS.d/next/Security/2026-08-10-12-00-00.gh-issue-156293.sNIcbk.rst
D Misc/NEWS.d/next/Security/2026-08-13-13-08-11.gh-issue-155999.Xt4rWq.rst
D Misc/NEWS.d/next/Security/2026-08-18-13-54-05.gh-issue-156002.CcWXPP.rst
D Misc/NEWS.d/next/Security/2026-08-31-16-47-33.gh-issue-157953.KxCF5N.rst
D Misc/NEWS.d/next/Security/2026-09-06-11-02-46.gh-issue-157190.tarhln.rst
D Misc/NEWS.d/next/Security/2026-09-10-13-38-11.gh-issue-157265.-vYuMp.rst
D Misc/NEWS.d/next/Security/2026-09-16-14-05-19.gh-issue-156793.Qa1T5Z.rst
D Misc/NEWS.d/next/Security/2026-09-23-11-34-30.gh-issue-156793.zC_AjF.rst
D Misc/NEWS.d/next/Security/2026-09-29-16-32-46.gh-issue-158446.dToaPr.rst
M Doc/library/asyncio-eventloop.rst
M Doc/library/ssl.rst
M Doc/library/tarfile.rst
M Doc/library/urllib.request.rst
M Include/patchlevel.h
M Lib/pydoc_data/topics.py
M README.rst
diff --git a/Doc/library/asyncio-eventloop.rst
b/Doc/library/asyncio-eventloop.rst
index d9b183733bd8bf9..a00154b1cc0a771 100644
--- a/Doc/library/asyncio-eventloop.rst
+++ b/Doc/library/asyncio-eventloop.rst
@@ -505,7 +505,7 @@ Opening network connections
For more information: https://tools.ietf.org/html/rfc6555
- .. versionchanged:: next
+ .. versionchanged:: 3.10.22
Raises a ``DeprecationWarning`` if ``ssl.check_hostname`` is ``True``
and ``server_hostname`` is not supplied. In Python 3.13 and
later a ``ValueError`` is raised instead.
diff --git a/Doc/library/ssl.rst b/Doc/library/ssl.rst
index 9d0663595717adb..ed602e8915f48f2 100644
--- a/Doc/library/ssl.rst
+++ b/Doc/library/ssl.rst
@@ -1779,7 +1779,7 @@ to speed up repeated connections from the same clients.
.. versionadded:: 3.7
- .. versionchanged:: next
+ .. versionchanged:: 3.10.22
After the callback assigns a new :attr:`SSLSocket.context`, later
ClientHello messages on the connection are dispatched to the new
context's *sni_callback*.
@@ -1914,7 +1914,7 @@ to speed up repeated connections from the same clients.
The method returns on instance of :attr:`SSLContext.sslobject_class`
instead of hard-coded :class:`SSLObject`.
- .. versionchanged:: next
+ .. versionchanged:: 3.10.22
The *server_side*, *server_hostname* and *session* parameters are now
validated as :meth:`SSLContext.wrap_socket` validates them. Previously
a context with :attr:`~SSLContext.check_hostname` enabled and no
diff --git a/Doc/library/tarfile.rst b/Doc/library/tarfile.rst
index 4b1d377b15e23d2..a8fdef14d7b2538 100644
--- a/Doc/library/tarfile.rst
+++ b/Doc/library/tarfile.rst
@@ -962,7 +962,7 @@ reused in custom filters:
Return the modified ``TarInfo`` member.
- .. versionchanged:: next
+ .. versionchanged:: 3.10.22
Filenames containing ``..`` components are now normalized.
diff --git a/Doc/library/urllib.request.rst b/Doc/library/urllib.request.rst
index 6cc606536a953aa..ef52a4c6c469283 100644
--- a/Doc/library/urllib.request.rst
+++ b/Doc/library/urllib.request.rst
@@ -927,7 +927,7 @@ These methods are available on :class:`HTTPPasswordMgr` and
match authentication URIs with the same scheme or no scheme. A URI without a
scheme matches authentication URIs with any scheme.
- .. versionchanged:: next
+ .. versionchanged:: 3.10.22
Authentication credentials for URIs with a scheme are now scoped by
that scheme.
diff --git a/Include/patchlevel.h b/Include/patchlevel.h
index 5fb36393037eff5..d44eb4fa98c34d4 100644
--- a/Include/patchlevel.h
+++ b/Include/patchlevel.h
@@ -18,12 +18,12 @@
/*--start constants--*/
#define PY_MAJOR_VERSION 3
#define PY_MINOR_VERSION 10
-#define PY_MICRO_VERSION 21
+#define PY_MICRO_VERSION 22
#define PY_RELEASE_LEVEL PY_RELEASE_LEVEL_FINAL
#define PY_RELEASE_SERIAL 0
/* Version as a string */
-#define PY_VERSION "3.10.21+"
+#define PY_VERSION "3.10.22"
/*--end constants--*/
/* Version as a single 4-byte hex number, e.g. 0x010502B2 == 1.5.2b2.
diff --git a/Lib/pydoc_data/topics.py b/Lib/pydoc_data/topics.py
index 823cd9dff674f90..4509b967d43dc6b 100644
--- a/Lib/pydoc_data/topics.py
+++ b/Lib/pydoc_data/topics.py
@@ -1,5 +1,5 @@
# -*- coding: utf-8 -*-
-# Autogenerated by Sphinx on Thu Aug 13 00:02:25 2026
+# Autogenerated by Sphinx on Thu Oct 1 01:47:59 2026
topics = {'assert': 'The "assert" statement\n'
'**********************\n'
'\n'
diff --git a/Misc/NEWS.d/3.10.22.rst b/Misc/NEWS.d/3.10.22.rst
new file mode 100644
index 000000000000000..8f8888cd83bca91
--- /dev/null
+++ b/Misc/NEWS.d/3.10.22.rst
@@ -0,0 +1,171 @@
+.. date: 2026-09-29-16-32-46
+.. gh-issue: 158446
+.. nonce: dToaPr
+.. release date: 2026-10-01
+.. section: Security
+
+Fix a crash or incorrect output that could occur when formatting a
+:class:`float` or :class:`complex` with a precision close to the platform's
+``INT_MAX``. :c:func:`PyOS_double_to_string` now raises :exc:`ValueError`
+for any precision of that magnitude, regardless of presentation type or
+value, as the format string parsers already did for precisions above
+``INT_MAX``.
+
+..
+
+.. date: 2026-09-23-11-34-30
+.. gh-issue: 156793
+.. nonce: zC_AjF
+.. section: Security
+
+:mod:`asyncio`: :meth:`loop.start_tls() <asyncio.loop.start_tls>` and
+:meth:`loop.create_connection() <asyncio.loop.create_connection>` now
+validate the *server_hostname* argument if an :class:`ssl.SSLContext` is
+passed with *check_hostname* set to ``True``, emitting
+:exc:`DeprecationWarning` if *server_hostname* is missing. (This will raise
+:exc:`ValueError` in Python 3.13 and later.)
+
+..
+
+.. date: 2026-09-16-14-05-19
+.. gh-issue: 156793
+.. nonce: Qa1T5Z
+.. section: Security
+
+:meth:`ssl.SSLContext.wrap_bio` now validates its *server_side*,
+*server_hostname* and *session* arguments similar to
+:meth:`ssl.SSLContext.wrap_socket`, but for backward compatiblity reasons
+emits :exc:`DeprecationWarning` instead of :exc:`ValueError`.
+
+In particular, a context with :attr:`~ssl.SSLContext.check_hostname` enabled
+and no *server_hostname* passed to :meth:`!wrap_bio` now emits
+:exc:`DeprecationWarning` to indicate the hostname wasn't checked. (In
+Python 3.13 and later, this raises :exc:`ValueError`.)
+
+..
+
+.. date: 2026-09-10-13-38-11
+.. gh-issue: 157265
+.. nonce: -vYuMp
+.. section: Security
+
+In :mod:`tarfile`, when extracting a link falls back to extracting a member
+of the archive, skip the member when the filter function returns None when
+called with the extracted member's name replaced with the link's.
+
+..
+
+.. date: 2026-09-06-11-02-46
+.. gh-issue: 157190
+.. nonce: tarhln
+.. section: Security
+
+Fixed a vulnerability in the :mod:`tarfile` ``data`` and ``tar`` extraction
+filters where a crafted archive using a hard link to a symbolic link could
+change the permissions and modification time of a file outside the
+destination directory, and expose its contents inside the extracted tree.
+This addresses CVE 2026-82049.
+
+..
+
+.. date: 2026-08-31-16-47-33
+.. gh-issue: 157953
+.. nonce: KxCF5N
+.. section: Security
+
+Update bundled `libexpat <https://libexpat.github.io/>`_ to version 2.8.5.
+
+..
+
+.. date: 2026-08-18-13-54-05
+.. gh-issue: 156002
+.. nonce: CcWXPP
+.. section: Security
+
+Bound the amount of data :mod:`zipfile` decompresses per read for members
+compressed with bzip2, LZMA, or Zstandard, matching the existing limit for
+deflate. A small archive member could previously expand into an unbounded
+allocation even when read in small chunks.
+
+..
+
+.. date: 2026-08-13-13-08-11
+.. gh-issue: 155999
+.. nonce: Xt4rWq
+.. section: Security
+
+Fix the :mod:`tarfile` ``tar`` and ``data`` extraction filters creating
+directories outside the destination for members whose name leaves the
+destination and returns to it, such as ``../evil/../dest/sub/file``. The
+containment check used the resolved path, but intermediate directories were
+created from the name as given.
+
+..
+
+.. date: 2026-08-10-12-00-00
+.. gh-issue: 156293
+.. nonce: sNIcbk
+.. section: Security
+
+Fix a crash in :mod:`ssl` when an :attr:`~ssl.SSLContext.sni_callback`
+switches a connection to another :class:`~ssl.SSLContext` and the context
+that carries the callback is no longer referenced by the application.
+Servers that keep their ``sni_callback`` context alive (the usual case when
+it wraps the listening socket or is stored on the server object) were not
+affected. This addresses `CVE-2026-19445
+<https://www.cve.org/CVERecord?id=CVE-2026-19445>`_.
+
+..
+
+.. date: 2026-08-06-11-43-20
+.. gh-issue: 155292
+.. nonce: j4pHBO
+.. section: Security
+
+Change the :mod:`stringprep` module and :mod:`encodings.idna` codec to not
+consider Unicode codepoint attributes beyond those defined in :rfc:`3454`.
+
+..
+
+.. date: 2026-07-31-16-20-17
+.. gh-issue: 155694
+.. nonce: SsxlKG
+.. section: Security
+
+Fix `CVE-2026-15806 <https://www.cve.org/CVERecord?id=CVE-2026-15806>`_ by
+scoping :class:`~urllib.request.HTTPPasswordMgr` credentials to the URL
+scheme, preventing credentials stored for an HTTPS URL from being used for a
+matching HTTP URL, while URIs without a scheme continue to match any scheme.
+
+..
+
+.. date: 2026-04-26-19-30-45
+.. gh-issue: 149018
+.. nonce: a9SqWb
+.. section: Security
+
+Improved protection against XML hash-flooding attacks in
+:mod:`xml.parsers.expat` and :mod:`xml.etree.ElementTree` when Python is
+compiled with libExpat 2.8.0 or later.
+
+..
+
+.. date: 2026-09-08-13-06-29
+.. gh-issue: 156002
+.. nonce: vmOC8T
+.. section: Library
+
+:mod:`zipfile` again reads members through a third-party decompressor
+installed by monkey-patching the private ``_get_decompressor()`` to return
+an object that only implements old BZ2Decompressor API from Python 3.3. Note
+that decompressors without ``needs_input`` and two-argument ``decompress()``
+are vulnerable to CVE 2026-15310.
+
+..
+
+.. date: 2026-08-26-02-30-00
+.. gh-issue: 156353
+.. nonce: abcdef
+.. section: Library
+
+Fix :mod:`configparser` parsing when using whitespace in *delimiters*.
diff --git
a/Misc/NEWS.d/next/Library/2026-08-26-02-30-00.gh-issue-156353.abcdef.rst
b/Misc/NEWS.d/next/Library/2026-08-26-02-30-00.gh-issue-156353.abcdef.rst
deleted file mode 100644
index 0dd925cf596277a..000000000000000
--- a/Misc/NEWS.d/next/Library/2026-08-26-02-30-00.gh-issue-156353.abcdef.rst
+++ /dev/null
@@ -1 +0,0 @@
-Fix :mod:`configparser` parsing when using whitespace in *delimiters*.
diff --git
a/Misc/NEWS.d/next/Library/2026-09-08-13-06-29.gh-issue-156002.vmOC8T.rst
b/Misc/NEWS.d/next/Library/2026-09-08-13-06-29.gh-issue-156002.vmOC8T.rst
deleted file mode 100644
index 689967bff72fe7c..000000000000000
--- a/Misc/NEWS.d/next/Library/2026-09-08-13-06-29.gh-issue-156002.vmOC8T.rst
+++ /dev/null
@@ -1,5 +0,0 @@
-:mod:`zipfile` again reads members through a third-party decompressor
-installed by monkey-patching the private ``_get_decompressor()`` to return an
-object that only implements old BZ2Decompressor API from Python 3.3.
-Note that decompressors without ``needs_input`` and two-argument
-``decompress()`` are vulnerable to CVE 2026-15310.
diff --git
a/Misc/NEWS.d/next/Security/2026-04-26-19-30-45.gh-issue-149018.a9SqWb.rst
b/Misc/NEWS.d/next/Security/2026-04-26-19-30-45.gh-issue-149018.a9SqWb.rst
deleted file mode 100644
index d1b5b368684e6a5..000000000000000
--- a/Misc/NEWS.d/next/Security/2026-04-26-19-30-45.gh-issue-149018.a9SqWb.rst
+++ /dev/null
@@ -1,3 +0,0 @@
-Improved protection against XML hash-flooding attacks in
-:mod:`xml.parsers.expat` and :mod:`xml.etree.ElementTree` when Python is
-compiled with libExpat 2.8.0 or later.
diff --git
a/Misc/NEWS.d/next/Security/2026-07-31-16-20-17.gh-issue-155694.SsxlKG.rst
b/Misc/NEWS.d/next/Security/2026-07-31-16-20-17.gh-issue-155694.SsxlKG.rst
deleted file mode 100644
index e85d482715a83c4..000000000000000
--- a/Misc/NEWS.d/next/Security/2026-07-31-16-20-17.gh-issue-155694.SsxlKG.rst
+++ /dev/null
@@ -1,4 +0,0 @@
-Fix `CVE-2026-15806 <https://www.cve.org/CVERecord?id=CVE-2026-15806>`_ by
scoping :class:`~urllib.request.HTTPPasswordMgr`
-credentials to the URL scheme, preventing credentials stored for an HTTPS
-URL from being used for a matching HTTP URL, while URIs without a scheme
-continue to match any scheme.
diff --git
a/Misc/NEWS.d/next/Security/2026-08-06-11-43-20.gh-issue-155292.j4pHBO.rst
b/Misc/NEWS.d/next/Security/2026-08-06-11-43-20.gh-issue-155292.j4pHBO.rst
deleted file mode 100644
index 7a81a8ba1eef1cd..000000000000000
--- a/Misc/NEWS.d/next/Security/2026-08-06-11-43-20.gh-issue-155292.j4pHBO.rst
+++ /dev/null
@@ -1,2 +0,0 @@
-Change the :mod:`stringprep` module and :mod:`encodings.idna` codec to not
-consider Unicode codepoint attributes beyond those defined in :rfc:`3454`.
diff --git
a/Misc/NEWS.d/next/Security/2026-08-10-12-00-00.gh-issue-156293.sNIcbk.rst
b/Misc/NEWS.d/next/Security/2026-08-10-12-00-00.gh-issue-156293.sNIcbk.rst
deleted file mode 100644
index 75b4ad2e3bc81fa..000000000000000
--- a/Misc/NEWS.d/next/Security/2026-08-10-12-00-00.gh-issue-156293.sNIcbk.rst
+++ /dev/null
@@ -1,7 +0,0 @@
-Fix a crash in :mod:`ssl` when an :attr:`~ssl.SSLContext.sni_callback`
-switches a connection to another :class:`~ssl.SSLContext` and the context
-that carries the callback is no longer referenced by the application.
-Servers that keep their ``sni_callback`` context alive (the usual case when
-it wraps the listening socket or is stored on the server object) were not
-affected.
-This addresses `CVE-2026-19445
<https://www.cve.org/CVERecord?id=CVE-2026-19445>`_.
diff --git
a/Misc/NEWS.d/next/Security/2026-08-13-13-08-11.gh-issue-155999.Xt4rWq.rst
b/Misc/NEWS.d/next/Security/2026-08-13-13-08-11.gh-issue-155999.Xt4rWq.rst
deleted file mode 100644
index 59b725e55bbffda..000000000000000
--- a/Misc/NEWS.d/next/Security/2026-08-13-13-08-11.gh-issue-155999.Xt4rWq.rst
+++ /dev/null
@@ -1,5 +0,0 @@
-Fix the :mod:`tarfile` ``tar`` and ``data`` extraction filters creating
-directories outside the destination for members whose name leaves the
-destination and returns to it, such as ``../evil/../dest/sub/file``. The
-containment check used the resolved path, but intermediate directories were
-created from the name as given.
diff --git
a/Misc/NEWS.d/next/Security/2026-08-18-13-54-05.gh-issue-156002.CcWXPP.rst
b/Misc/NEWS.d/next/Security/2026-08-18-13-54-05.gh-issue-156002.CcWXPP.rst
deleted file mode 100644
index 4e49ad5ce8fa00a..000000000000000
--- a/Misc/NEWS.d/next/Security/2026-08-18-13-54-05.gh-issue-156002.CcWXPP.rst
+++ /dev/null
@@ -1,4 +0,0 @@
-Bound the amount of data :mod:`zipfile` decompresses per read for members
-compressed with bzip2, LZMA, or Zstandard, matching the existing limit for
-deflate. A small archive member could previously expand into an unbounded
-allocation even when read in small chunks.
diff --git
a/Misc/NEWS.d/next/Security/2026-08-31-16-47-33.gh-issue-157953.KxCF5N.rst
b/Misc/NEWS.d/next/Security/2026-08-31-16-47-33.gh-issue-157953.KxCF5N.rst
deleted file mode 100644
index 5b3ea77cb368632..000000000000000
--- a/Misc/NEWS.d/next/Security/2026-08-31-16-47-33.gh-issue-157953.KxCF5N.rst
+++ /dev/null
@@ -1 +0,0 @@
-Update bundled `libexpat <https://libexpat.github.io/>`_ to version 2.8.5.
diff --git
a/Misc/NEWS.d/next/Security/2026-09-06-11-02-46.gh-issue-157190.tarhln.rst
b/Misc/NEWS.d/next/Security/2026-09-06-11-02-46.gh-issue-157190.tarhln.rst
deleted file mode 100644
index c3aac4084c1859c..000000000000000
--- a/Misc/NEWS.d/next/Security/2026-09-06-11-02-46.gh-issue-157190.tarhln.rst
+++ /dev/null
@@ -1,5 +0,0 @@
-Fixed a vulnerability in the :mod:`tarfile` ``data`` and ``tar`` extraction
-filters where a crafted archive using a hard link to a symbolic link could
-change the permissions and modification time of a file outside the
-destination directory, and expose its contents inside the extracted tree.
-This addresses CVE 2026-82049.
diff --git
a/Misc/NEWS.d/next/Security/2026-09-10-13-38-11.gh-issue-157265.-vYuMp.rst
b/Misc/NEWS.d/next/Security/2026-09-10-13-38-11.gh-issue-157265.-vYuMp.rst
deleted file mode 100644
index ba27e47f734bfb1..000000000000000
--- a/Misc/NEWS.d/next/Security/2026-09-10-13-38-11.gh-issue-157265.-vYuMp.rst
+++ /dev/null
@@ -1,3 +0,0 @@
-In :mod:`tarfile`, when extracting a link falls back to extracting a member
-of the archive, skip the member when the filter function returns None when
-called with the extracted member's name replaced with the link's.
diff --git
a/Misc/NEWS.d/next/Security/2026-09-16-14-05-19.gh-issue-156793.Qa1T5Z.rst
b/Misc/NEWS.d/next/Security/2026-09-16-14-05-19.gh-issue-156793.Qa1T5Z.rst
deleted file mode 100644
index ce43a563f3a1df0..000000000000000
--- a/Misc/NEWS.d/next/Security/2026-09-16-14-05-19.gh-issue-156793.Qa1T5Z.rst
+++ /dev/null
@@ -1,9 +0,0 @@
-:meth:`ssl.SSLContext.wrap_bio` now validates its *server_side*,
-*server_hostname* and *session* arguments similar to
-:meth:`ssl.SSLContext.wrap_socket`, but for backward compatiblity reasons
-emits :exc:`DeprecationWarning` instead of :exc:`ValueError`.
-
-In particular, a context with :attr:`~ssl.SSLContext.check_hostname` enabled
-and no *server_hostname* passed to :meth:`!wrap_bio` now emits
-:exc:`DeprecationWarning` to indicate the hostname wasn't checked.
-(In Python 3.13 and later, this raises :exc:`ValueError`.)
diff --git
a/Misc/NEWS.d/next/Security/2026-09-23-11-34-30.gh-issue-156793.zC_AjF.rst
b/Misc/NEWS.d/next/Security/2026-09-23-11-34-30.gh-issue-156793.zC_AjF.rst
deleted file mode 100644
index 9afd6e9c454aaff..000000000000000
--- a/Misc/NEWS.d/next/Security/2026-09-23-11-34-30.gh-issue-156793.zC_AjF.rst
+++ /dev/null
@@ -1,6 +0,0 @@
-:mod:`asyncio`: :meth:`loop.start_tls() <asyncio.loop.start_tls>` and
-:meth:`loop.create_connection() <asyncio.loop.create_connection>` now
-validate the *server_hostname* argument if an :class:`ssl.SSLContext` is
-passed with *check_hostname* set to ``True``, emitting
-:exc:`DeprecationWarning` if *server_hostname* is missing. (This will raise
-:exc:`ValueError` in Python 3.13 and later.)
diff --git
a/Misc/NEWS.d/next/Security/2026-09-29-16-32-46.gh-issue-158446.dToaPr.rst
b/Misc/NEWS.d/next/Security/2026-09-29-16-32-46.gh-issue-158446.dToaPr.rst
deleted file mode 100644
index f17a3f68b93e855..000000000000000
--- a/Misc/NEWS.d/next/Security/2026-09-29-16-32-46.gh-issue-158446.dToaPr.rst
+++ /dev/null
@@ -1,5 +0,0 @@
-Fix a crash or incorrect output that could occur when formatting a
-:class:`float` or :class:`complex` with a precision close to the platform's
-``INT_MAX``. :c:func:`PyOS_double_to_string` now raises :exc:`ValueError` for
-any precision of that magnitude, regardless of presentation type or value, as
-the format string parsers already did for precisions above ``INT_MAX``.
diff --git a/README.rst b/README.rst
index a6ca0030032056c..ffb8f1623e6449c 100644
--- a/README.rst
+++ b/README.rst
@@ -1,5 +1,5 @@
-This is Python version 3.10.21+
-===============================
+This is Python version 3.10.22
+==============================
.. image:: https://travis-ci.com/python/cpython.svg?branch=master
:alt: CPython build status on Travis CI
_______________________________________________
Python-checkins mailing list -- [email protected]
To unsubscribe send an email to [email protected]
https://mail.python.org/mailman3//lists/python-checkins.python.org
Member address: [email protected]