Registro de cambios
En esta página
- Python next#
- macOS#
- Windows#
- Tools/Demos#
- Tests#
- Security#
- Library#
- IDLE#
- Documentation#
- Core and Builtins#
- C API#
- Build#
- Python 3.14.6 final#
- Security#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- C API#
- Python 3.14.5 final#
- Security#
- Core and Builtins#
- Library#
- Tests#
- macOS#
- Python 3.14.5 release candidate 1#
- Security#
- Core and Builtins#
- Library#
- Documentation#
- Build#
- Windows#
- macOS#
- Python 3.14.4 final#
- Security#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- C API#
- Python 3.14.3 final#
- Windows#
- Tools/Demos#
- Tests#
- Security#
- Library#
- IDLE#
- Documentation#
- Core and Builtins#
- C API#
- Build#
- Python 3.14.2 final#
- Security#
- Library#
- Core and Builtins#
- Library#
- Python 3.14.1 final#
- Windows#
- Tools/Demos#
- Tests#
- Security#
- Library#
- IDLE#
- Documentation#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- C API#
- Build#
- Python 3.14.0 final#
- macOS#
- Windows#
- Tools/Demos#
- Security#
- Library#
- Python 3.14.0 release candidate 3#
- Windows#
- Tools/Demos#
- Security#
- Library#
- Core and Builtins#
- Python 3.14.0 release candidate 2#
- macOS#
- Windows#
- Library#
- Documentation#
- Core and Builtins#
- C API#
- Build#
- Python 3.14.0 release candidate 1#
- Tools/Demos#
- Security#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- C API#
- Build#
- Python 3.14.0 beta 4#
- Tools/Demos#
- Tests#
- Security#
- Library#
- Documentation#
- Core and Builtins#
- C API#
- Build#
- Python 3.14.0 beta 3#
- Windows#
- Tests#
- Security#
- Library#
- Documentation#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- C API#
- Build#
- Python 3.14.0 beta 2#
- Windows#
- Tools/Demos#
- Tests#
- Security#
- Library#
- Core and Builtins#
- C API#
- Build#
- Python 3.14.0 beta 1#
- Windows#
- Tools/Demos#
- Tests#
- Security#
- Library#
- IDLE#
- Documentation#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- C API#
- Build#
- Python 3.14.0 alpha 7#
- macOS#
- Windows#
- Tools/Demos#
- Tests#
- Security#
- Library#
- Documentation#
- Core and Builtins#
- Library#
- Core and Builtins#
- C API#
- Build#
- Python 3.14.0 alpha 6#
- macOS#
- Windows#
- Tools/Demos#
- Tests#
- Security#
- Library#
- Documentation#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- C API#
- Build#
- Python 3.14.0 alpha 5#
- macOS#
- Tools/Demos#
- Tests#
- Security#
- Library#
- IDLE#
- Documentation#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- C API#
- Build#
- Python 3.14.0 alpha 4#
- macOS#
- Tools/Demos#
- Tests#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- C API#
- Build#
- Python 3.14.0 alpha 3#
- Windows#
- Tools/Demos#
- Tests#
- Security#
- Library#
- Documentation#
- Core and Builtins#
- Library#
- Core and Builtins#
- C API#
- Build#
- Python 3.14.0 alpha 2#
- Windows#
- Tools/Demos#
- Tests#
- Security#
- Library#
- Documentation#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- C API#
- Build#
- Python 3.14.0 alpha 1#
- macOS#
- Windows#
- Tools/Demos#
- Tests#
- Security#
- Library#
- IDLE#
- Documentation#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- C API#
- Build#
- Python 3.13.0 beta 1#
- Security#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Documentation#
- Build#
- Windows#
- macOS#
- IDLE#
- C API#
- Python 3.13.0 alpha 6#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- C API#
- Python 3.13.0 alpha 5#
- Security#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- Tools/Demos#
- C API#
- Python 3.13.0 alpha 4#
- Security#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- Tools/Demos#
- C API#
- Python 3.13.0 alpha 3#
- Security#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- C API#
- Python 3.13.0 alpha 2#
- Core and Builtins#
- Library#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- Tools/Demos#
- C API#
- Python 3.13.0 alpha 1#
- Security#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- Tools/Demos#
- C API#
- Python 3.12.0 beta 1#
- Security#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- Tools/Demos#
- C API#
- Python 3.12.0 alpha 7#
- Core and Builtins#
- Library#
- Core and Builtins#
- Build#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- Tools/Demos#
- C API#
- Python 3.12.0 alpha 6#
- Security#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- C API#
- Python 3.12.0 alpha 5#
- Security#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- Python 3.12.0 alpha 4#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- Tools/Demos#
- C API#
- Python 3.12.0 alpha 3#
- Security#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- Tools/Demos#
- C API#
- Python 3.12.0 alpha 2#
- Security#
- Core and Builtins#
- Build#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- C API#
- Python 3.12.0 alpha 1#
- Security#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- Tools/Demos#
- C API#
- Python 3.11.0 beta 1#
- Security#
- Core and Builtins#
- Library#
- Core and Builtins#
- Build#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- Tools/Demos#
- C API#
- Python 3.11.0 alpha 7#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- Tools/Demos#
- C API#
- Python 3.11.0 alpha 6#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- IDLE#
- C API#
- Python 3.11.0 alpha 5#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Build#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- C API#
- Python 3.11.0 alpha 4#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- C API#
- Python 3.11.0 alpha 3#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- C API#
- Python 3.11.0 alpha 2#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- C API#
- Python 3.11.0 alpha 1#
- Security#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- Tools/Demos#
- C API#
- Python 3.10.0 beta 1#
- Security#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- C API#
- Python 3.10.0 alpha 7#
- Security#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- IDLE#
- C API#
- Python 3.10.0 alpha 6#
- Security#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- C API#
- Python 3.10.0 alpha 5#
- Security#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- C API#
- Python 3.10.0 alpha 4#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- macOS#
- Tools/Demos#
- C API#
- Python 3.10.0 alpha 3#
- Security#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- Tools/Demos#
- C API#
- Python 3.10.0 alpha 2#
- Security#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- C API#
- Python 3.10.0 alpha 1#
- Security#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- C API#
- Python 3.9.0 beta 1#
- Security#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- Tools/Demos#
- C API#
- Python 3.9.0 alpha 6#
- Security#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- Tools/Demos#
- C API#
- Python 3.9.0 alpha 5#
- Security#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- Tools/Demos#
- C API#
- Python 3.9.0 alpha 4#
- Security#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- IDLE#
- C API#
- Python 3.9.0 alpha 3#
- Core and Builtins#
- Library#
- Documentation#
- Build#
- IDLE#
- C API#
- Python 3.9.0 alpha 2#
- Security#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- C API#
- Python 3.9.0 alpha 1#
- Security#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- Tools/Demos#
- C API#
- Python 3.8.0 beta 1#
- Security#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- Tools/Demos#
- C API#
- Python 3.8.0 alpha 4#
- Security#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- Tools/Demos#
- C API#
- Python 3.8.0 alpha 3#
- Security#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- IDLE#
- Tools/Demos#
- C API#
- Python 3.8.0 alpha 2#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Windows#
- IDLE#
- Python 3.8.0 alpha 1#
- Security#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- Tools/Demos#
- C API#
- Python 3.7.0 final#
- Library#
- C API#
- Python 3.7.0 release candidate 1#
- Core and Builtins#
- Library#
- Documentation#
- Build#
- Windows#
- IDLE#
- Python 3.7.0 beta 5#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- macOS#
- IDLE#
- Python 3.7.0 beta 4#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- Tools/Demos#
- Python 3.7.0 beta 3#
- Security#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- Tools/Demos#
- C API#
- Python 3.7.0 beta 2#
- Security#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- Tools/Demos#
- Python 3.7.0 beta 1#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- C API#
- Python 3.7.0 alpha 4#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Windows#
- Tools/Demos#
- C API#
- Python 3.7.0 alpha 3#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- Tools/Demos#
- C API#
- Python 3.7.0 alpha 2#
- Core and Builtins#
- Library#
- Documentation#
- Build#
- IDLE#
- C API#
- Python 3.7.0 alpha 1#
- Security#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- IDLE#
- Tools/Demos#
- C API#
- Python 3.6.6 final#
- Python 3.6.6 release candidate 1#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- Tools/Demos#
- C API#
- Python 3.6.5 final#
- Tests#
- Build#
- Python 3.6.5 release candidate 1#
- Security#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- Tools/Demos#
- C API#
- Python 3.6.4 final#
- Python 3.6.4 release candidate 1#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- macOS#
- IDLE#
- Tools/Demos#
- C API#
- Python 3.6.3 final#
- Library#
- Build#
- Python 3.6.3 release candidate 1#
- Security#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- IDLE#
- Tools/Demos#
- Python 3.6.2 final#
- Python 3.6.2 release candidate 2#
- Security#
- Python 3.6.2 release candidate 1#
- Security#
- Core and Builtins#
- Library#
- IDLE#
- C API#
- Build#
- Documentation#
- Tools/Demos#
- Tests#
- Windows#
- Python 3.6.1 final#
- Core and Builtins#
- Build#
- Python 3.6.1 release candidate 1#
- Core and Builtins#
- Library#
- IDLE#
- Windows#
- C API#
- Documentation#
- Tests#
- Build#
- Python 3.6.0 final#
- Python 3.6.0 release candidate 2#
- Core and Builtins#
- Tools/Demos#
- Windows#
- Build#
- Python 3.6.0 release candidate 1#
- Core and Builtins#
- Library#
- C API#
- Documentation#
- Tools/Demos#
- Python 3.6.0 beta 4#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Python 3.6.0 beta 3#
- Core and Builtins#
- Library#
- Windows#
- Build#
- Tests#
- Python 3.6.0 beta 2#
- Core and Builtins#
- Library#
- Windows#
- C API#
- Build#
- Tests#
- Python 3.6.0 beta 1#
- Core and Builtins#
- Library#
- IDLE#
- C API#
- Tests#
- Build#
- Tools/Demos#
- Windows#
- Python 3.6.0 alpha 4#
- Core and Builtins#
- Library#
- IDLE#
- Tests#
- Windows#
- Build#
- Python 3.6.0 alpha 3#
- Security#
- Core and Builtins#
- Library#
- IDLE#
- C API#
- Build#
- Tools/Demos#
- Documentation#
- Tests#
- Python 3.6.0 alpha 2#
- Security#
- Core and Builtins#
- Library#
- IDLE#
- Documentation#
- Tests#
- Windows#
- Build#
- C API#
- Tools/Demos#
- Python 3.6.0 alpha 1#
- Security#
- Core and Builtins#
- Library#
- IDLE#
- Documentation#
- Tests#
- Build#
- Windows#
- Tools/Demos#
- C API#
- Python 3.5.5 final#
- Python 3.5.5 release candidate 1#
- Security#
- Core and Builtins#
- Library#
- Python 3.5.4 final#
- Library#
- Python 3.5.4 release candidate 1#
- Security#
- Core and Builtins#
- Library#
- Documentation#
- Tests#
- Build#
- Windows#
- C API#
- Python 3.5.3 final#
- Python 3.5.3 release candidate 1#
- Security#
- Core and Builtins#
- Library#
- IDLE#
- C API#
- Documentation#
- Tests#
- Tools/Demos#
- Windows#
- Build#
- Python 3.5.2 final#
- Core and Builtins#
- Tests#
- IDLE#
- Python 3.5.2 release candidate 1#
- Security#
- Core and Builtins#
- Library#
- IDLE#
- Documentation#
- Tests#
- Build#
- Windows#
- Tools/Demos#
- Python 3.5.1 final#
- Core and Builtins#
- Windows#
- Python 3.5.1 release candidate 1#
- Core and Builtins#
- Library#
- IDLE#
- Documentation#
- Tests#
- Build#
- Windows#
- Tools/Demos#
- Python 3.5.0 final#
- Build#
- Python 3.5.0 release candidate 4#
- Library#
- Build#
- Python 3.5.0 release candidate 3#
- Core and Builtins#
- Library#
- Python 3.5.0 release candidate 2#
- Core and Builtins#
- Library#
- Python 3.5.0 release candidate 1#
- Core and Builtins#
- Library#
- IDLE#
- Documentation#
- Tests#
- Python 3.5.0 beta 4#
- Core and Builtins#
- Library#
- Build#
- Python 3.5.0 beta 3#
- Core and Builtins#
- Library#
- Tests#
- Documentation#
- Build#
- Python 3.5.0 beta 2#
- Core and Builtins#
- Library#
- Python 3.5.0 beta 1#
- Core and Builtins#
- Library#
- IDLE#
- Tests#
- Documentation#
- Tools/Demos#
- Python 3.5.0 alpha 4#
- Core and Builtins#
- Library#
- Build#
- Tests#
- Tools/Demos#
- C API#
- Python 3.5.0 alpha 3#
- Core and Builtins#
- Library#
- Build#
- Tests#
- Tools/Demos#
- Python 3.5.0 alpha 2#
- Core and Builtins#
- Library#
- Build#
- C API#
- Windows#
- Python 3.5.0 alpha 1#
- Core and Builtins#
- Library#
- IDLE#
- Build#
- C API#
- Documentation#
- Tests#
- Tools/Demos#
- Windows#
Registro de cambios#
Python next#
Release date: XXXX-XX-XX
macOS#
- gh-124111: Update macOS installer to use Tcl/Tk 9.0.4.
Windows#
- gh-140146: Prevent "tkinter" from hanging on Windows if stdin is redirected to a pipe in an interactive session. This is helpful for testing interactive usage of tkinter from a script, for example as part of the cpython test suite.
Tools/Demos#
- gh-154580: Fix "python-gdb.py" raising "UnicodeEncodeError" when pretty-printing a non-ASCII "str" in a locale whose host charset cannot encode it, such as any non-ASCII string in the C locale.
Tests#
-
gh-76595: Add C API tests for "PyCapsule_Import()".
-
gh-154211: Add "test.support.skip_if_huge_c_stack()" and use it to skip tests that exhaust the C stack if the stack limit is very large (e.g. on DragonFly BSD or with "ulimit -s unlimited").
-
gh-154167: The test runner (regrtest) now restores the default SIGINT handler if it was inherited as ignored, so the test suite no longer hangs when run as a shell background job.
-
gh-154144: Fix building the "_testcapi" module on NetBSD.
-
gh-152548: Add the "test.support.isolation.runInSubprocess()" decorator to run a test method or "TestCase" subclass in a fresh interpreter subprocess, isolated from the rest of the test run.
-
gh-151626: Fix several tests in "test.test_inspect", "test.test_import", "test.test_importlib", "test.test_py_compile" and "test.test_compileall" that failed when the test suite was run with "PYTHONPYCACHEPREFIX" set. These tests now neutralize the pycache prefix where they assume the default "pycache" bytecode layout.
-
gh-151096: Fix "test_embed" failing when CPython is configured with a split exec prefix ("--exec-prefix" differing from "--prefix").
-
gh-148853: Fix tests failing on FreeBSD in test.support's in_systemd_nspawn_sync_suppressed() due to unreadable /run directory.
Security#
-
gh-153030: Fixed quadratic complexity in incremental parsing of long unterminated constructs (such as tags or comments) in "html.parser.HTMLParser", which could be exploited for a denial of service.
-
gh-152674: The "xml.etree.ElementTree.Element" methods "findall()", "iterfind()" and "find()" avoid quadratic behavior when using XPath index predicates ("[1]", "[last()]", "[last()-N]") on XML documents with many same-tag siblings.
-
gh-152216: Update bundled libexpat to version 2.8.2.
-
gh-151987: The "tarfile.TarFile.extract()" method now applies the given filter when it extracts a link target from the archive as a fallback.
-
gh-151981: In "tarfile", seeking a stream now stops when end of the stream is reached.
-
gh-151544: "Modules/Setup.local" is no longer used as a landmark to discover whether Python is running in a source tree, as it could potentially affect actual installs. The "pybuilddir.txt" file is now the sole indicator of running in a source tree.
-
gh-151558: Fixed an vulnerability in the "tarfile" "data" and "tar" extraction filters where crafted archives could create a symlink pointing outside the destination directory. This was a bypass of CVE 2025-4330.
-
gh-150743: "http.client" now limits the number of chunked-response trailer lines it will read to 100, and the number of interim (1xx) responses it will skip to 100. A malicious or broken server could previously stream trailer lines or "100 Continue" responses forever, hanging the client even when a socket timeout was in use. Reported by "@YLChen-007" via GHSA-w4q2-g22w-6fr4.
-
gh-143927: Normalize all line endings (CR, CRLF, and LF) to LF+TAB when writing multi-line configparser values.
-
gh-143921: Reject NUL, CR and LF characters in IMAP commands. Other control characters are allowed and sent quoted.
Library#
-
gh-154936: Fix the pure Python "json" decoder to report the correct position for invalid literal control characters in JSON strings.
-
gh-154848: The "pickle" C accelerator now enforces frame boundaries when unpickling, as the pure Python implementation already did. An argument that straddles a frame boundary, or a frame that begins before the previous one has ended, now raises "pickle.UnpicklingError" instead of being silently read across the boundary. This prevents the loaded data from diverging from the "pickletools" disassembly of the same pickle.
-
gh-93251: Fix "UnicodeDecodeError" in "socket" functions (such as "getaddrinfo()" and "gethostbyaddr()") when the localized error message of the C library is not UTF-8: decode it from the locale encoding.
-
gh-154551: Fix "ctypes.util.find_library()" returning "None" in non- UTF-8 locales.
-
gh-73458: Fix "logging.config.listen()": it left the caller waiting for the "ready" event forever if the server could not be started, for example if the port was invalid or already in use. It now also binds to an IPv6 address if the host has no IPv4 address, for example if "localhost" is only aliased to "::1".
-
gh-154460: Fix "time.strftime()" and "datetime.datetime.strftime()" returning a wrong ISO 8601 week number ("%V") on OpenBSD.
-
gh-154435: Fix "os.posix_fadvise()" and "os.posix_fallocate()" on DragonFly BSD: they raised "OSError" with a meaningless error code, because these functions return -1 and set "errno" there.
-
gh-154399: Fix "venv" activation in a non-interactive csh: "activate.csh" no longer fails when the "prompt" variable is not set.
-
gh-154389: Fix "uuid.uuid1()" on OpenBSD: it returned a version 4 UUID, because "uuid_create()" generates random UUIDs on this platform.
-
gh-154324: Fix "os.sendfile()" on illumos: it no longer reports a successful transfer when the underlying system call failed without writing any data.
-
gh-154307: Fix "tempfile.TemporaryDirectory.cleanup()" on DragonFly BSD, where removing a file with the "UF_NOUNLINK" flag failed with "EISDIR" instead of "EPERM".
-
gh-154291: Fix "socket.has_dualstack_ipv6()" to return "False" on platforms such as DragonFly BSD where setting "IPV6_V6ONLY" to 0 silently has no effect.
-
gh-154283: On DragonFly BSD, "threading.get_native_id()" now returns a value that is unique across processes, matching the other platforms.
-
gh-154258: Fix a crash in "mmap.mmap.resize()" on NetBSD when growing a shared anonymous mapping. "resize()" now raises "ValueError" in this case, as it already did on Linux.
-
gh-131565: "ctypes.util.dllist()" now works on NetBSD. It is implemented in the "_ctypes" extension module so that "dl_iterate_phdr()" reports all loaded shared libraries: on NetBSD it only reports the link-map group of the calling object, which excluded them when called through ctypes.
-
gh-154225: Fix "os.openpty()" on Solaris and illumos: it no longer leaves the pseudo-terminal as the controlling terminal of the calling process.
-
gh-154227: Fix "os.posix_openpt()" on OpenBSD, where it rejected the "O_CLOEXEC" flag.
-
gh-145030: Fix "asyncio" write pipe transports for named FIFOs on macOS. Unread data sitting in the FIFO made the transport misinterpret a poll event as the reader disconnecting, wrongly closing the transport.
-
gh-154001: Fix "random.binomialvariate()" raising "ZeroDivisionError" when "random.random()" returns zero.
-
gh-153908: Fix data race when calling "repr()" on "itertools.count" under the free-threaded build.
-
gh-153896: Deduplicate unhashable args in "typing.Literal".
-
gh-153864: On a wide "curses" build, "curses.window.insch()" now inserts a non-ASCII byte as the character it encodes in the window's encoding, consistently with "addch()", instead of its code point.
-
gh-153862: On a wide "curses" build, "curses.window.inch()" now returns the locale-encoded byte of a non-ASCII character, matching "instr()", instead of the low byte of its code point.
-
gh-146011: Fix a heap-use-after-free in the C implementation of "decimal" when calling "repr()" after deleting the "Context".
-
gh-153761: Fix cancelling "asyncio.loop.sock_accept()" dropping a pending connection.
-
gh-153695: Hashing a "sqlite3.Row" that contains an unhashable value now raises "TypeError" instead of "SystemError". Patch by tonghuaroot.
-
gh-127049: Fix a race condition in "asyncio" on Unix where "asyncio.subprocess.Process.send_signal()", "terminate()" or "kill()" could signal an unrelated process that was recycled onto the PID of the already-reaped child when ThreadedChildWatcher is used. Patch by Kumar Aditya.
-
gh-153658: Fix "sqlite3.Connection.iterdump()" raising "sqlite3.OperationalError" when a table name contains a single quote. Patch by tonghuaroot.
-
gh-85943: Fix "struct" functions raising "BytesWarning" under the "-bb" command line option when a "str" format is used after an equal "bytes" format (or vice versa). The internal format cache no longer mixes "str" and "bytes" keys.
-
gh-153404: "urllib.robotparser.RobotFileParser" now silently ignores a "Crawl-delay" or "Request-rate" value written with non-decimal digits (such as "U+00B2 SUPERSCRIPT TWO") instead of raising "ValueError" and aborting the parse of the whole "robots.txt" file.
-
gh-153417: Error messages from "imaplib.IMAP4.select()" and "imaplib.IMAP4.uid()" no longer raise "BytesWarning" under "-bb" when the mailbox or command argument is "bytes".
-
gh-153406: "email.utils.parsedate_to_datetime()" now raises "ValueError" instead of "OverflowError" when the parsed year or timezone offset is out of range, matching its documented behavior.
-
gh-153083: Defer GC tracking of an "array.array" to the end of its construction. Patch by Donghee Na.
-
gh-153292: Fix data race in repr of "threading.RLock" in free- threading build.
-
gh-143990: A "tkinter.font.Font" created from a named font, including by "copy()", now copies its configured options rather than the options resolved by Tcl's "font actual", preserving a size specified in pixels (a negative size).
-
gh-148286: Fix undefined behavior in "compression.zstd.ZstdDecompressor.unused_data" when a complete frame was decompressed in a single call.
-
gh-153210: Fix crash on "array" import under a memory pressure.
-
gh-153200: Fix "math.isqrt()" returning an incorrect result for arguments not less than 2**64 that are instances of an "int" subclass with an overridden comparison operator.
-
gh-153068: Fix "cProfile.Profile.enable()" to no longer overwrite errors from "sys.monitoring".
-
gh-153062: Fix a crash when concurrently iterating an "itertools.tee()" iterator on the free-threaded build.
-
gh-153056: Fix "string.Template" raising a spurious "ValueError" when the pattern attribute is a compiled regular expression object, which the documentation allows. On the free-threaded build this also occurred as a data race on the first concurrent use.
-
gh-153037: Fix "ZstdFile" raising "AttributeError" instead of "io.UnsupportedOperation" when iterating over a file that is not open for reading.
-
gh-135661: Fix "html.parser.HTMLParser": an abruptly closed empty comment ("<!-->" or "") no longer extends up to a later "-->" in the same "feed()" call.
-
gh-152851: Prevent a crash when allocation fails while copying a "BLAKE-2s/2b" object. Patch by Bénédikt Tran.
-
gh-54930: Error responses of "http.server.BaseHTTPRequestHandler" to malformed request lines now include a status line and headers instead of being sent in the bare HTTP/0.9 style. Only a valid HTTP/0.9 request (a two-word "GET" request line) now receives an HTTP/0.9 style response.
-
gh-119592: Fix "concurrent.futures.ProcessPoolExecutor" stranding submitted work forever when a worker process exited upon reaching its max_tasks_per_child limit after "shutdown()" was called with "wait=False": a replacement worker is now spawned and the remaining work executed as documented. If the executor has instead been garbage collected without "shutdown()" (gh-152967), or a replacement worker cannot be started, the remaining futures now fail with "BrokenProcessPool" instead of never resolving. A worker exit racing "shutdown(wait=False)" can also no longer crash the executor management thread.
-
gh-152951: "collections.deque" prevent rare crash when calling "extend" under high memory pressure conditions.
-
gh-150880: Normalize non-extended Windows paths before appending the wildcard used by "os.listdir()" and "os.scandir()", making paths with trailing spaces behave consistently with other filesystem APIs.
-
gh-152849: Out-of-range float and integer timestamps now raise "OverflowError" with the same message. Patch by tonghuaroot.
-
gh-152847: Reject a POSIX TZ transition rule with non-digit characters in the day-of-year field in the pure-Python "zoneinfo" parser. Patch by tonghuaroot.
-
gh-108280: Connecting "imaplib" to a server that does not send a valid IMAP4 greeting (for example a POP3 server answering on the IMAP port) now raises an error reporting the server's response instead of "imaplib.IMAP4.error: None".
-
gh-63121: "imaplib" now refreshes the cached capability list after a successful "login()" or "authenticate()", using the "CAPABILITY" response sent by the server or, if none was sent, by querying it, so that capabilities that become available only after authentication (such as "ENABLE" on Gmail) are recognized. Capabilities advertised in the server greeting are now also used, avoiding a redundant "CAPABILITY" command.
-
gh-88574: "imaplib" no longer fails when a server sends a spurious blank line after the counted data of a literal, including after a literal that terminates a response (such as a mailbox name returned by "LIST"). Such blank lines are now skipped without swallowing the following line.
-
gh-152502: Detect the "curses" mouse interface ("getmouse()", the "BUTTON*" constants, and others) with a configure capability probe or library macros instead of gating it on ncurses-specific macros. It is now also available with other curses implementations that provide it, such as NetBSD curses and PDCurses (the latter underpins "windows-curses").
-
gh-151842: Fix a crash in "_interpreters.capture_exception()" when "MemoryError" happens. Patch by Amrutha Modela.
-
gh-40038: "imaplib" now again quotes command arguments when necessary, for example mailbox names containing a space. Such quoting was inadvertently disabled when the module was ported to Python 3, and the arguments are now quoted according to the RFC 3501 grammar. For backward compatibility, an argument already enclosed in double quotes is left unchanged, so code that quotes arguments itself keeps working.
-
gh-50966: Fix unbounded recursion in "turtle" when a mouse event handler that moves the turtle is reentered while the screen is being redrawn, for example with "screen.ondrag(turtle.goto)". This could previously crash the interpreter.
-
gh-152569: Fix "asyncio.wait()" leaking waiting tasks via the await- graph when racing a future that never resolves. The waiting task is now discarded from every future's "awaited_by" set once "wait()" returns, even for pending futures.
-
gh-78335: Update the docstrings of "tkinter" and "tkinter.ttk" widget classes to list all supported widget options, including options added in Tk 9.0 and 9.1. "tkinter.Menubutton" and "tkinter.Message" previously had no option list at all.
-
gh-152431: Fix "asyncio.StreamWriter.start_tls()" to keep the linked "StreamReader" transport in sync with the upgraded transport.
-
gh-151126: Fix two crashes in "tkinter" and "socket" modules initialization under a memory pressure. Sets missing "MemoryError".
-
gh-133031: "curses.textpad.Textbox" now enters and reads back the non-ASCII characters of an 8-bit locale encoding, instead of mangling them with a 7-bit mask.
-
gh-71880: "curses.textpad.Textbox" now lets the lower-right cell of the window be edited. Writing it with "addch()" would move the cursor past the end of the window, raising an error and scrolling a scrollable window, so it is now written with "insch()", which keeps the cursor in place.
-
gh-83274: Deallocating a "tkinter" application from a thread other than the one it was created in no longer crashes the interpreter. The underlying Tcl interpreter is leaked instead, and a "RuntimeWarning" is reported.
-
gh-152305: Fix the pure-Python "datetime.time.strftime()" implementation raising "AttributeError" for the year directives. Patch by tonghuaroot.
-
gh-88758: "tkinter.Misc.focus_get()", "focus_displayof()", "focus_lastfor()" and "winfo_containing()" now return "None" instead of raising "KeyError" when the widget was not created by "tkinter" (for example a torn-off menu).
-
gh-38464: "tkinter.Misc.nametowidget()" now resolves the auto- generated names of cloned menus (a menu used as a menubar or a cascade) back to the original widget.
-
gh-152248: Make the C and pure-Python "zoneinfo" parsers validate POSIX TZ abbreviations consistently, rejecting unquoted abbreviations with non-letter characters and empty quoted abbreviations. Patch by tonghuaroot.
-
gh-80937: Fix a memory leak in "tkinter" when a Tcl command created with "createcommand" was not explicitly removed before the interpreter was deleted. The command no longer keeps the interpreter alive through a reference cycle.
-
gh-152246: Fix the pure-Python "zoneinfo" parser accepting an invalid POSIX TZ transition rule with a non-period separator. Patch by tonghuaroot.
-
gh-139816: Fix a hang in "tkinter" on interactive Python built without "readline". An exception raised in a callback no longer causes the event loop to stop and wait for the user to press Enter; pending callbacks now keep running until input is actually available on stdin.
-
gh-139145: Fix a busy loop in "tkinter" on interactive Python. When a Tcl command running its own event loop (such as "vwait" or "wait_variable()") was active and input arrived on stdin, the event loop kept spinning at 100% CPU. The stdin file handler is now removed as soon as input is available. Based on a patch by Michiel de Hoon.
-
gh-152212: Fix the pure-Python "zoneinfo" parser accepting a POSIX TZ string with a "std" abbreviation but no offset. This is invalid per POSIX and now raises "ValueError", matching the C accelerator. Patch by tonghuaroot.
-
gh-152156: Fix a possible crash in "concurrent.interpreters.create()" under limited memory conditions.
-
gh-152157: The C implementations of "fromisoformat()" and "fromisoformat()" now reject a decimal separator that is not followed by any fractional digit before a timezone designator.
-
gh-151763: Fix crash in "_interpqueues.create()" whe "MemoryError" happens on queue creation.
-
gh-105895: Add "match" and "case" to the list of supported topics by "help()".
-
gh-152079: Fix "datetime.datetime.fromisoformat()" in the C implementation dropping the sub-second part of a UTC offset whose whole-second part is zero, matching the pure-Python implementation.
-
gh-152052: The "json" C accelerator now correctly reports an unterminated string for a "\uXXXX" escape at the end of the input.
-
gh-152060: Fix "datetime.datetime.fromisoformat()" raising "AssertionError" instead of "ValueError" for some malformed strings in the pure-Python implementation, matching the C implementation.
-
gh-126219: Fixed a crash in "tkinter.Tk" when className contains a non-BMP character and tkinter is built against Tcl/Tk 8.x. Such a name is now rejected with a "ValueError".
-
gh-86165: Fix "imaplib.Time2Internaldate()" to use the local timezone offset for "time.struct_time" values with "tm_gmtoff" set to "None", as returned by "datetime.datetime.timetuple()". Contributed by Xiao Yuan.
-
gh-151814: Fix unbounded memory growth in "io.TextIOWrapper" when repeatedly writing an empty string.
-
gh-151770: Fix "datetime.datetime.fromisoformat()" raising "AssertionError" instead of "ValueError" for an out-of-range month combined with a "24:00" time.
-
gh-151665: "inspect.signature()" now works on the lazy evaluators of type aliases and type parameters instead of raising "ValueError".
-
gh-151695: Fix a use-after-free in the "curses" module. The encoding of the initial screen, used by "curses.unctrl()" and "curses.ungetch()" to encode non-ASCII characters, is now kept as a private copy instead of a borrowed pointer to a window object that may be deallocated.
-
gh-151596: Add missing "size" positional argument to the pure-Python implementation of "io.TextIOBase.readline()".
-
gh-151640: Fix a data race in "io.BytesIO" in free-threaded builds when whole-buffer reads or peeks, or "getvalue()", share the internal buffer with concurrent writes.
-
gh-148660: Fix a crash in "collections.OrderedDict.copy()" when a key's "eq" or a subclass method mutates the dict during the copy. Now raises "RuntimeError" instead, as iteration does.
-
gh-151497: Opening a "tarfile" archive no longer attempts to pre- allocate a huge buffer when a crafted or truncated member claims an oversized extended header (a GNU long name/link or a pax header). The extended header is now read in bounded chunks, so its size field can no longer trigger memory exhaustion.
-
gh-151403: Fixed a crash in "subprocess.Popen" (and "_posixsubprocess.fork_exec") when an "argv" item's "fspath()" concurrently mutates the "args" sequence being converted.
-
gh-151390: Colorize "match" in the REPL when followed by a unary "+" or "-" operator. Patch by Bartosz Sławecki.
-
gh-151126: Fix crash on unset "MemoryError" on allocation failure in "ctypes.get_errno()".
-
gh-151416: Fix a crash in "os.spawnv()" and "os.spawnve()" when an argv item's "fspath()" method mutates the argv list during argument conversion. "os.spawnv()" argument conversion errors other than "TypeError", such as the "ValueError" for an embedded null, are no longer replaced with a generic "TypeError".
-
gh-151337: Avoid possible memory leak in "tkinter.c" on Windows.
-
gh-151126: Fix a crash when "MemoryError" in "os._path_splitroot()" was not set properly.
-
gh-151126: Fix a crash, when there's no memory left on a device, which happened in "_interpchannels" module.
Now it raises proper "MemoryError" errors.
-
gh-119710: Fix "asyncio" subprocess "wait()" hanging when the process has exited but one of its pipes is kept open by an inherited child process (so the pipe never reaches EOF). "wait()" now returns as soon as the process exits, regardless of the pipes' state.
-
gh-151295: Fixed a crash (use-after-free) in "bytes.join()" and "bytearray.join()" that could occur if an item's "buffer()" concurrently mutates the sequence being joined. The mutation is now reported as a "RuntimeError" instead.
-
gh-109940: Fix Windows "venv" activation in "cmd.exe" to respect "VIRTUAL_ENV_DISABLE_PROMPT".
-
gh-150583: Correctly set the default compression level in "compression.zstd" when passing a digested dictionary during compression.
-
gh-150641: Fix bug where "typing.evaluate_forward_ref()" with the "STRING" format could leak internal names used by the annotation machinery.
-
gh-150484: Fix "unittest.mock.mock_open()" "exit" raising "TypeError" when used with "contextlib.ExitStack".
-
gh-149816: Fix a potential use after free condition in "pickle.dumps()" in free-threaded mode when serializing lists.
-
gh-149319: The "asyncio" REPL now ignores "PYTHONSTARTUP" and "PYTHON_BASIC_REPL" when "-E" or "-I" is used. Patch by Jonathan Dung.
-
gh-47005: Fix "urllib.request.AbstractHTTPHandler.do_open()" to give regular headers set via "add_header()" priority over unredirected headers, consistent with "get_header()" and "header_items()".
-
gh-123471: Make concurrent iteration over "itertools.zip_longest" safe under free-threading.
-
gh-123720: asyncio: Fix "asyncio.Server.serve_forever()" shutdown regression. Since 3.12, cancelling "serve_forever()" could hang waiting for a handler blocked on a read from a client that never closed (effectively requiring two interrupts to stop); the shutdown sequence now ensures client streams are closed so "serve_forever()" exits promptly and handlers observe EOF.
-
gh-123471: Make concurrent iteration over "itertools.accumulate" safe under free-threading.
-
gh-123471: Make concurrent iteration over "itertools.combinations_with_replacement" and "itertools.permutations" safe under free-threading.
-
gh-143988: Fixed crashes in "socket.socket.sendmsg()" and "socket.socket.recvmsg_into()" that could occur if buffer sequences are concurrently mutated.
-
gh-130796: Undeprecate the "locale.getdefaultlocale()" function. Patch by Victor Stinner.
-
gh-115634: Fix a deadlock in "concurrent.futures.ProcessPoolExecutor" when using "max_tasks_per_child", present since the feature was introduced in Python 3.11. The executor stopped scheduling queued tasks after a worker process exited upon reaching its task limit. Based on a fix proposed by Tabrez Mohammed.
-
gh-140326: Fix the "asyncio" REPL namespace so that relative imports no longer resolve against the "asyncio" package and "file" is no longer set.
-
gh-79638: Disallow all access in "urllib.robotparser" if the "robots.txt" file is unreachable due to server or network errors.
-
gh-123471: Make concurrent iterations over "itertools.chain" safe under free threading.
-
gh-123471: Make concurrent iterations over "itertools.combinations" and "itertools.product" safe under free-threading.
-
gh-123471: Make concurrent iterations over "itertools.cycle" safe under free-threading.
-
gh-120665: Fixed an issue where "unittest" loaders would load and instantiate "unittest.TestCase"-derived subclasses that are also abstract base classes, which can't be instantiated.
-
gh-105708: Accept an uppercase V prefix in IPvFuture addresses in "urllib.parse.urlsplit()".
-
gh-103925: Fix "csv.Sniffer.sniff()" for a sample with "\r\n" line endings in which a quoted field ends a line: a letter could be detected as the delimiter.
-
gh-101267: When a worker process terminates unexpectedly, "concurrent.futures.ProcessPoolExecutor" now sets a separate "BrokenProcessPool" exception on each pending future instead of sharing a single instance among them all. Sharing one exception produced malformed tracebacks: each "Future.result()" call re-raised the same object, appending another copy of the traceback to it.
IDLE#
-
gh-82183: When the shell is busy running code, using "Run... Customized" with "Restart shell" unchecked now reports that the shell is executing instead of restarting it anyway.
-
gh-83653: Blanking an integer entry in IDLE's Settings dialog, such as "Auto squeeze min lines", no longer saves an empty string as an invalid configuration value.
-
gh-65339: Saving the IDLE Shell or an Output window now defaults to a ".txt" extension and lists text files before Python files, since their content is not Python source.
-
gh-80504: The "In files:" field of IDLE's Find in Files dialog now always contains a full directory path, even for an unsaved editor or the Shell. This shows in the grep output which directory was searched.
-
gh-134300: Do not add the "idlelib" directory to the path of the IDLE user process. User code run in IDLE can no longer import "idlelib" submodules as top-level modules, such as "import help".
-
gh-89360: Fix a rare crash in the IDLE editor when the completion window is closed: deleting a key binding for a sequence that is not bound to the virtual event is now ignored instead of raising a "ValueError".
-
gh-71956: Fix Replace All in the IDLE editor's Replace dialog when the search direction is "Up" and "Wrap around" is off: it now replaces all matches above the current position instead of only the first one.
-
gh-152728: Move functions run.fix_scaling, editor.fixwordbreaks (as fix_word_breaks) and pyshell.fix_x11_paste to idlelib.util.
-
gh-66331: Set the "WM_CLASS" window property of IDLE's windows to "Idle" on X11, so that window managers group and label them correctly instead of using the default "Toplevel".
-
gh-85320: IDLE now reads and writes its configuration files and the breakpoints file using UTF-8 instead of the locale encoding. This keeps non-ASCII data (such as non-ASCII paths) from being corrupted and makes the files portable between environments.
-
gh-94523: Detect file if modified at local disk and prompt to ask refresh. Patch by Shixian Li.
-
gh-139551: Support rendering "BaseExceptionGroup" in IDLE.
-
gh-89520: Make IDLE extension configuration look at user config files, allowing user-installed extensions to have settings and key bindings defined in ~/.idlerc.
Documentation#
-
gh-118150: Clarify in the "difflib" documentation what junk actually does, its drawbacks, and how to control it.
-
gh-86726: Greatly expand the "tkinter" documentation to cover the full public API of the package and its submodules. The descriptions are oriented towards Python rather than Tcl/Tk, with corrected return types and "versionadded"/"versionchanged" information.
Core and Builtins#
-
gh-133931: Fix data races when setting attributes of function objects on the free threaded build.
-
gh-154709: Fix an out-of-bounds access in reverse dictionary iterators when the underlying dictionary is cleared and modified after the iterator is created.
-
gh-154695: Fix "asyncio.Task" raising "AttributeError" when created with "eager_start=True" and no explicit loop argument.
-
gh-153809: Fix interpreter crash while deallocating objects of "asyncio.Task" on free-threaded builds. Contributed by Sergey Miryanov.
-
gh-154275: Fix a crash when getting deeply nested "parameters" from a "types.GenericAlias" objects.
-
gh-153932: Fix thread safety issue in the "reduce" method of "enumerate".
-
gh-153298: Fixes a data race in "types.GenericAlias" "parameters" initialization on free-threading builds.
-
gh-153205: Fix a potential "SystemError" during vector calls when memory allocation fails. A "MemoryError" is now raised instead.
-
gh-152682: Fix NULL pointer dereference in "compile()" when a reserved name (e.g. "classdict") is used as a type parameter name and memory allocation fails while formatting the error message.
-
gh-152635: Fix a crash caused when running out of memory creating a "_interpchannels" channel. Now a "MemoryError" is correctly raised.
-
gh-152375: Fix undefined behaviour when a "sys.monitoring" callback raised an exception while the program was following a branch or loop.
-
gh-152235: Defer GC tracking of "set.intersection()", "set.difference()", "set.symmetric_difference()", "set.union()" and "set.sub". Patch by Donghee Na.
-
gh-152235: Defer GC tracking of a "set" or "frozenset" to the end of its construction from iterable. Patch by Donghee Na.
-
gh-152228: Fix an assertion failure when python is built in a debug mode that happened in "str.replace()" under a limited memory situation.
-
gh-151763: Fixes possible crash on "types.CodeType" deallocation.
-
gh-152020: On the free-threaded build, "asyncio.all_tasks()" no longer loses eager-started tasks when called from a thread other than the one running the event loop.
-
gh-151763: Fix a potential crash in "compile()", "exec()", "eval()" and "ast.parse()" when an allocation fails: the parser or compiler could return without setting an exception.
-
gh-151912: Fixed a crash in "type()" when selecting a metaclass whose "tp_new" slot is "NULL". Such metaclasses are now rejected with "TypeError" instead of causing a NULL pointer dereference.
-
gh-151905: Fix OOM error handling in "PyFrame_GetBack()" to propagate exceptions instead of masking them as None.
-
gh-151773: Fix a crash in "contextvars.ContextVar.set()" when memory allocation fails.
-
gh-151126: Fix a crash when sharing "memoryview" objects between interpreters fails due to running out of memory. It now raises a proper "MemoryError".
-
gh-151644: Fix a data race in "sys.setdlopenflags()" and "sys.getdlopenflags()" when called concurrently in the free-threaded build. The underlying "_PyImport_GetDLOpenFlags" and "_PyImport_SetDLOpenFlags" functions now use atomic load/store operations.
-
gh-151126: Avoid possible crash in "_winapi.c" where a device has no memory left. Now it properly raises a "MemoryError". Patch by Ivy Xu.
-
gh-151546: Fix the stack limit check if Python is linked to musl (ex: Alpine Linux). Use the stack size set by the linker to compute the stack limits. Patch by Victor Stinner.
-
gh-151461: Fix direct execution of files with invalid source encodings to report the underlying codec lookup or decoding error instead of the generic "SyntaxError: encoding problem" message. Patch by Bartosz Sławecki.
-
gh-151218: "PyConfig_Set()" and "sys.set_int_max_str_digits()" now replace "sys.flags" (create a new object), instead of modifying "sys.flags" in-place. Patch by Victor Stinner.
-
gh-151253: If "import encodings" (first import) fails at Python startup, dump the Python path configuration to help users debugging their configuration. Patch by Victor Stinner.
-
gh-151238: Fix a crash when compiling a concatenated f-string or t-string if an error occurs when processing one of it's parts.
-
gh-151126: Fix a crash, when there's no memory left on a device, which happened in "_interpchannels" module.
Now it raises proper "MemoryError" errors.
-
gh-150902: Apply an existing optimization of PyCriticalSection (single mutex) to PyCriticalSection2: avoid acquiring the same locks that the current CS has already acquired.
-
gh-151065: Fix memory leak when using the mimalloc memory allocator.
-
gh-151029: On Linux, fix "sys.remote_exec()" unable to find remote writable memory when "libpython" replaced on disk.
-
gh-150988: Fix a reference leak in "OSError" when attributes are set before "super().init()".
-
gh-144774: Fix data race in "BaseException" when an exception is copied while being mutated.
-
gh-150411: Fix a data race in the free-threaded build when "gc.get_count()" reads the young generation allocation count while another thread updates it.
-
gh-149689: Fix missing error propagation in parser action helpers when memory allocation fails. Patch by Thomas Kowalski.
-
gh-149162: Fix a potential deadlock in "PyUnicode_InternFromString()" and other interning functions in the free-threaded build when called from C++ static local initializers.
C API#
-
gh-152132: Fix "Py_RunMain()" to return an exit code, rather than calling "Py_Exit()", when running a script, a command, or the REPL. Patch by Victor Stinner.
-
gh-153300: "PyConfig_Set()" now also set global configuration variables. For example, "PyConfig_Set("inspect", value)" now also sets "Py_InspectFlag". Patch by Victor Stinner.
-
gh-123619: "PyUnstable_Object_EnableDeferredRefcount()" now returns "0" if the object is not tracked by the garbage collector: if "gc.is_tracked()" is false. Patch by Victor Stinner.
Build#
-
gh-154070: Build the "curses" module against a wide-character capable ncurses even when it is not named "ncursesw" -- for example the pkgsrc ncurses on NetBSD and illumos, or the system ncurses on macOS. Such a library previously produced a narrow build.
-
gh-126877: Fix the configure check for Tcl/Tk which could wrongly succeed with optimizing compilers when the libraries are missing.
-
gh-153438: Update Windows build and installer tooling and documentation to use the current download URL for "nuget.exe".
-
gh-152502: The "curses" module now detects "set_escdelay()", "set_tabsize()" and the "ESCDELAY" and "TABSIZE" variables with configure capability probes instead of the ncurses-specific "NCURSES_EXT_FUNCS" macro, so they are exposed when building against other curses implementations such as NetBSD curses that provide them.
-
gh-148260: On Linux when Python is linked to the musl C library, use a thread stack size of at least 1 MiB instead of musl default which is 128 kiB. Patch by Victor Stinner.
Python 3.14.6 final#
Release date: 2026-06-10
Security#
-
gh-151159: Update Android and iOS installers to use OpenSSL 3.5.7.
-
gh-150599: Fix a possible stack buffer overflow in "bz2" when a "bz2.BZ2Decompressor" is reused after a decompression error. The decompressor now becomes unusable after libbz2 reports an error.
-
gh-149835: "shutil.move()" now resolves symlinks via "os.path.realpath()" when checking whether the destination is inside the source directory, preventing a symlink-based bypass of that guard.
-
gh-149698: Update bundled libexpat to version 2.8.1 for the fix for CVE 2026-45186.
-
gh-87451: The "ftplib" module's undocumented "ftpcp" function no longer trusts the IPv4 address value returned from the source server in response to the "PASV" command by default, completing the fix for CVE-2021-4189. As with "ftplib.FTP", the former behavior can be re- enabled by setting the "trust_server_pasv_ipv4_address" attribute on the source "ftplib.FTP" instance to "True". Thanks to Qi Deng at Aurascape AI for the report.
-
gh-149486: "tarfile.data_filter()" now validates link targets using the same normalised value that is written to disk, strips trailing separators from the member name when resolving a symlink's directory, and rejects link members that would replace the destination directory itself. This closes several path-traversal bypasses of the "data" extraction filter.
-
gh-149079: Fix a potential denial of service in "unicodedata.normalize()". The canonical ordering step of Unicode normalization used a quadratic-time insertion sort for reordering combining characters, which could be exploited with crafted input containing many combining characters in non-canonical order. Replaced with a linear-time counting sort for long runs.
-
gh-149018: Improved protection against XML hash-flooding attacks in "xml.parsers.expat" and "xml.etree.ElementTree" when Python is compiled with libExpat 2.8.0 or later.
Core and Builtins#
-
gh-151112: Fix a crash in the compiler that could occur when running out of memory.
-
gh-151126: Fix a crash, when there's no memory left on a device, which happened in:
-
code compilation - "_winapi.CreateProcess()"
Now these places raise proper "MemoryError" errors.
-
gh-150700: Fix a "SystemError" when compiling a class-scope comprehension containing a "lambda" that references "class", "classdict", or "conditional_annotations". Patch by Bartosz Sławecki.
-
gh-150633: Fix the frozen importer accepting module names with embedded null bytes, which caused it to bypass the "sys.modules" cache and create duplicate module objects.
-
gh-148613: Fix a data race in the free-threaded build between "gc.set_threshold()" and garbage collection scheduling during object allocation.
-
gh-149156: Fix an intermittent crash after "os.fork()" when perf trampoline profiling is enabled and the child returns through trampoline frames inherited from the parent process.
-
gh-149449: Fix a use-after-free crash when the "unicodedata" module was removed from "sys.modules" and garbage-collected between calls that decode "\N{...}" escapes or use the "namereplace" codec error handler.
-
gh-150207: Fix a crash when a memory allocation fails during tokenizer initialization. A proper "MemoryError" is now raised instead.
-
gh-150107: "asyncio": "sendfile()" and "sock_sendfile()" event loop methods now call "file.seek(offset)" if file has a "seek()" method, even if offset is "0" (default value).
-
gh-150146: Fix a crash on a complex type variable substitution.
"from typing import TypeVar; memoryview[TypeVar("")][*typing.Mapping[..., ...]]" used to fail due to missing "NULL" check on "_unpack_args" C function call.
-
gh-149590: Fix crash when faulthandler is imported more than once.
-
gh-149816: Fix a race condition in "_PyBytes_FromList" in free- threading mode.
-
gh-149816: Fix a race condition in "memoryview" with free-threading.
-
gh-149805: Fix a "SystemError" when compiling a compiling "classdict" class annotation. Found by OSS-Fuzz in #512907042.
-
gh-149738: "sqlite3": Disallow removing "row_factory" and "text_factory" attributes of a connection to prevent a crash on a query.
-
gh-139808: Add branch protections for AArch64 (BTI/PAC) in assembly code used by "-X perf_jit" (Linux perf profiler integration).
-
gh-148450: Fix "abc.register()" so it invalidates type version tags for registered classes.
Library#
-
gh-151039: Fix a crash when static "datetime" types outlive the "_datetime" module.
-
gh-150913: Fix "sqlite3.Blob" slice assignment to raise "TypeError" and "IndexError" for type and size mismatches respectively, even when the target slice is empty.
-
gh-143008: Fix race conditions when re-initializing a "io.TextIOWrapper" object.
-
gh-150750: Fix a race condition in "collections.deque.index()" with free-threading.
-
gh-150685: Update bundled pip to 26.1.2
-
gh-150406: Fix a possible crash occurring during "socket" module initialization when the system is out of memory on platforms without a reentrant "gethostbyname".
-
gh-150372: "readline": Fix a potential crash during tab completion caused by an out-of-memory error during module initialization.
-
gh-150157: Fix a crash in free-threaded builds that occurs when pickling by name objects without a "module" attribute while "sys.modules" is concurrently being modified.
-
gh-150175: Fix race condition in "unittest.mock.ThreadingMock" where concurrent calls could lose increments to "call_count" and other attributes due to a missing lock in "_increment_mock_call".
-
gh-84353: Preserve non-UTF-8 encoded filenames when appending to a "zipfile.ZipFile". Previously, non-ASCII names stored in a legacy encoding (without the UTF-8 flag bit set) could be corrupted when the central directory was rewritten: they were decoded as cp437 and then re-stored as UTF-8.
-
gh-149816: Fix race condition in "ssl.SSLContext.sni_callback"
-
gh-149995: Update various docstrings in "typing".
-
gh-88726: The "email" package now uses standard MIME charset names "gb2312" and "big5" instead of non-standard names "eucgb2312_cn" and "big5_tw".
-
gh-149571: Fix the C implementation of "xml.etree.ElementTree.Element.itertext()": it no longer emits text for comments and processing instructions.
-
gh-149921: Fix reference leaks in error paths of the "_interpchannels" and "_interpqueues" extension modules.
-
gh-149816: Fix a race condition in "_random.Random.init" method in free-threading mode.
-
gh-149801: Add IANA registered names and aliases with leading zeros before number (like IBM00858, CP00858, IBM01140, CP01140) for corresponding codecs.
-
gh-149701: Fix bad return code from Lib/venv/bin/activate if hashing is disabled
-
gh-112821: In the REPL, autocompletion might run arbitrary code in the getter of a descriptor. If that getter raised an exception, autocompletion would fail to present any options for the entire object. Autocompletion now works as expected for these objects.
-
gh-149489: Fix "ElementTree" serialization to HTML. The content of elements "xmp", "iframe", "noembed", "noframes", and "plaintext" is no longer escaped. The "plaintext" element no longer have the closing tag.
-
gh-149231: In "tomllib", the number of parts in TOML keys is now limited.
-
gh-149046: "io": Fix "io.StringIO" serialization: no longer call "str(obj)" on "str" subclasses. Patch by Thomas Kowalski.
-
gh-148954: Fix XML injection vulnerability in "xmlrpc.client.dumps()" where the "methodname" was not being escaped before interpolation into the XML body.
-
gh-148441: "xml.parsers.expat": prevent a crash in "CharacterDataHandler()" when the character data size exceeds the parser's "buffer size".
-
gh-146452: Fix segfault in "pickle" when pickling a dictionary concurrently mutated by another thread in the free-threaded build.
-
gh-142831: Fix a crash in the "json" module where a use-after-free could occur if the object being encoded is modified during serialization.
-
gh-90949: Add "SetBillionLaughsAttackProtectionActivationThreshold()" and "SetBillionLaughsAttackProtectionMaximumAmplification()" to xmlparser objects to tune protections against billion laughs attacks. Patch by Bénédikt Tran.
-
gh-134261: zip: On reproducible builds, ZipFile uses UTC instead of the local time when writing file datetimes to avoid underflows.
-
gh-128110: Fix bug in the parsing of "email" address headers that could result in extraneous spaces in the decoded text when using a modern email policy. Space between pairs of adjacent RFC 2047 encoded-words is now ignored, per section 6.2 (and consistent with existing parsing of unstructured headers like Subject).
-
gh-107398: Fix "tarfile" stream mode exception when process the file with the gzip extra field.
-
gh-123853: Update the table of Windows language code identifiers (LCIDs) used by "locale.getdefaultlocale()" on Windows to protocol version 16.0 (2024-04-23).
-
gh-91099: "imaplib.IMAP4.login()" now raises exceptions with "str" instead of "bytes". Patch by Florian Best.
Documentation#
-
gh-150319: Generic builtin and standard library types now document the meaning of their type parameters.
-
gh-109503: Fix documentation for "shutil.move()" on usage of "os.rename()" since nonatomic move might be used even if the files are on the same filesystem. Patch by Fang Li
Tests#
-
gh-151130: Add more tests for "PyWeakref_*" C API.
-
gh-149776: Fix test_socket on Linux kernel 7.1 and newer: skip UDP Lite tests if it's not supported. Patch by Victor Stinner.
Build#
- gh-148294: Corrected the use of "AC_PATH_TOOL" in "configure.ac" to allow a C++ compiler to be found on "PATH".
Windows#
- gh-151159: Updated bundled version of OpenSSL to 3.5.7.
macOS#
-
gh-151159: Update macOS installer to use OpenSSL 3.5.7.
-
gh-150644: When system logging is enabled (with "config.use_system_logger", messages are now tagged as public. This allows the macOS 26 system logger to view messages without special configuration.
-
gh-115119: Update macOS installer to use libmpdecimal 4.0.1.
IDLE#
- bpo-6699: Warn the user if a file will be overwritten when saving.
C API#
-
gh-150907: Fix "dynamic_annotations.h" header file when built with C++ and Valgrind: add "extern "C++" scope" for the C++ template. Patch by Victor Stinner.
-
gh-145235: Made "PyDict_AddWatcher()", "PyDict_ClearWatcher()", "PyDict_Watch()", and "PyDict_Unwatch()" thread-safe on the free threaded build.
Python 3.14.5 final#
Release date: 2026-05-10
Security#
- gh-148178: Hardened "_remote_debugging" by validating remote debug offset tables before using them to size memory reads or interpret remote layouts.
Core and Builtins#
-
gh-146270: Fix a sequential consistency bug in "structmember.c".
-
gh-137293: Fix "SystemError" when searching ELF Files in "sys.remote_exec()".
Library#
-
gh-149388: Make "asyncio.windows_utils.PipeHandle" closing idempotent.
-
gh-149377: Update bundled pip to 26.1.1
-
gh-138907: Support RFC 9309 in "urllib.robotparser".
-
gh-148615: Fix "pdb" to accept standard -- end of options separator. Reported by haampie. Patched by Shrey Naithani.
-
gh-130750: Restore quoting of choices in "argparse" error messages for improved clarity and consistency with documentation.
-
gh-141449: Improve tests and documentation for non-function callables as annotate functions.
Tests#
-
gh-149425: Increase time delta in "test.test_zipfile.test_core.Othe rTests.test_write_without_source_date_epoch"
-
gh-145736: Fix test_tkinter test_configure_values test case backport miss for Tk 9.
macOS#
-
gh-142295: For Python macOS framework builds, update Info.plist files to be more compliant with current Apple guidelines. Original patch contributed by Martinus Verburg.
-
gh-124111: Update macOS installer to use Tcl/Tk 9.0.3.
Python 3.14.5 release candidate 1#
Release date: 2026-05-04
Security#
-
gh-149254: Update Android and iOS installer to use OpenSSL 3.0.20.
-
gh-149017: Update bundled libexpat to version 2.8.0.
-
gh-90309: Base64-encode values when embedding cookies to JavaScript using the "http.cookies.BaseCookie.js_output()" method to avoid injection and escaping.
-
gh-148808: Added buffer boundary check when using "nbytes" parameter with "asyncio.AbstractEventLoop.sock_recvfrom_into()". Only relevant for Windows and the "asyncio.ProactorEventLoop".
-
gh-148395: Fix a dangling input pointer in "lzma.LZMADecompressor", "bz2.BZ2Decompressor", and internal "zlib._ZlibDecompressor" when memory allocation fails with "MemoryError", which could let a subsequent "decompress()" call read or write through a stale pointer to the already-released caller buffer.
-
gh-148169: A bypass in "webbrowser" allowed URLs prefixed with "%action" to pass the dash-prefix safety check.
-
gh-146581: Fix vulnerability in "shutil.unpack_archive()" for ZIP files on Windows which allowed to write files outside of the destination tree if the patch in the archive contains a Windows drive prefix. Now such invalid paths will be skipped. Files containing ".." in the name (like "foo..bar") are no longer skipped.
-
gh-146333: Fix quadratic backtracking in "configparser.RawConfigParser" option parsing regexes ("OPTCRE" and "OPTCRE_NV"). A crafted configuration line with many whitespace characters could cause excessive CPU usage.
-
gh-146211: Reject CR/LF characters in tunnel request headers for the HTTPConnection.set_tunnel() method.
Core and Builtins#
-
gh-149122: Fix a crash in optimized calls to "all()", "any()", "tuple()", "list()", and "set()" with an async generator expression argument (for example, "tuple(await x for x in y)"). These calls now correctly raise "TypeError" instead of crashing.
-
gh-113956: Fix a data race in "sys.intern()" in the free-threaded build when interning a string owned by another thread. An interned copy owned by the current thread is used instead when it is not safe to immortalize the original.
-
gh-148820: Fix a race in "_PyRawMutex" on the free-threaded build where a "Py_PARK_INTR" return from "_PySemaphore_Wait" could let the waiter destroy its semaphore before the unlocking thread's "_PySemaphore_Wakeup" completed, causing a fatal "ReleaseSemaphore" error.
-
gh-148653: Forbid "marshalling" recursive code objects and "slice" objects which cannot be correctly unmarshalled.
-
gh-142516: Forward-port the generational cycle garbage collector to the default 3.14 build, replacing the incremental collector while leaving the free-threaded collector unchanged.
-
gh-148390: Fix an undefined behavior in "memoryview" when using the native boolean format ("?") in "cast()". Previously, on some common platforms, calling "memoryview(b).cast("?").tolist()" incorrectly returned "[False]" instead of "[True]" for any even byte b. Patch by Bénédikt Tran.
-
gh-148418: Fix a possible reference leak in a corrupted "TYPE_CODE" marshal stream.
-
gh-148393: Fix data races between "PyDict_Watch()" / "PyDict_Unwatch()" and concurrent dict mutation in the free- threaded build.
-
gh-148284: Fix high stack consumption in Python's interpreter loop on Clang 22 by setting function limits for inlining when building with computed gotos.
-
gh-148037: Remove critical section from "PyCode_Addr2Line()" in free-threading.
-
gh-148222: Fix vectorcall support in "types.GenericAlias" when the underlying type does not support the vectorcall protocol. Fix possible leaks in "types.GenericAlias" and "types.UnionType" in case of memory error.
-
gh-148208: Fix recursion depth leak in "PyObject_Print()"
-
gh-137814: Fix the "qualname" attribute of "annotate" functions on functions.
-
gh-147998: Fixed a memory leak in interpreter helper calls so cleanup works when an operation falls across interpreter boundaries. Patch by Maurycy Pawłowski-Wieroński.
-
gh-146455: Fix O(N²) compile-time regression in constant folding after it was moved from AST to CFG optimizer.
Library#
-
gh-149221: Catch rare math domain error for "random.binomialvariate()".
-
gh-149117: Fix "runpy.run_module()" and "runpy.run_path()" to set the "name" attribute on the "ImportError" they raise.
-
gh-149148: "ensurepip": Upgrade bundled pip to 26.1. This version fixes the CVE 2026-3219 vulnerability. Patch by Victor Stinner.
-
gh-148093: Fix an out-of-bounds read of one byte in "binascii.a2b_uu()". Raise "binascii.Error", instead of reading past the buffer end.
-
gh-148914: Fix memoization of in-band "PickleBuffer" in the Python implementation of "pickle". Previously, identical "PickleBuffer"s did not preserve identity, and empty writable "PickleBuffer" memoized an empty bytearray object in place of "b''", so the following references to "b''" were unpickled as an empty bytearray object.
-
gh-148947: Fix crash in "@dataclasses.dataclass" with "slots=True" that occurred when a function found within the class had an empty "class" cell.
-
gh-148680: "ForwardRef" objects that contain internal names to represent known objects now show the "type_repr" of the known object rather than the internal "annotationlib_name_x" name when evaluated as strings.
-
gh-148801: "xml.etree.ElementTree": Fix a crash in "Element.deepcopy" on deeply nested trees.
-
gh-148735: "xml.etree.ElementTree": Fix a use-after-free in "Element.findtext" when the element tree is mutated concurrently during the search.
-
gh-148740: Fix usage for "uuid" command-line interface to support a custom namespace be provided for uuid3 and uuid5.
-
gh-148651: Fix reference leak in "compression.zstd.ZstdDecompressor" when an invalid option key is passed.
-
gh-146553: Fix infinite loop in "typing.get_type_hints()" when "wrapped" forms a cycle. Patch by Shamil Abdulaev.
-
gh-148508: An intermittent timing error when running SSL tests on iOS has been resolved.
-
gh-148518: If an email containing an address header that ended in an open double quote was parsed with a non-"compat32" policy, accessing the "username" attribute of the mailbox accessed through that header object would result in an "IndexError". It now correctly returns an empty string as the result.
-
gh-148464: Add missing "ctype_le/be" attributes for "c_float_complex" and "c_double_complex". Patch by Sergey B Kirpichev.
-
gh-148370: "configparser": prevent quadratic behavior when a "ParsingError" is raised after a parser fails to parse multiple lines. Patch by Bénédikt Tran.
-
gh-148254: Use singular "sec" instead of "secs" in "timeit" verbose output for consistency with other time units.
-
gh-148192: "email.generator.Generator._make_boundary" could fail to detect a duplicate boundary string if linesep was not n. It now correctly detects boundary strings when linesep is rn as well.
-
gh-146313: Fix a deadlock in "multiprocessing"'s resource tracker where the parent process could hang indefinitely in "os.waitpid()" during interpreter shutdown if a child created via "os.fork()" still held the resource tracker's pipe open.
-
gh-145831: Fix "email.quoprimime.decode()" leaving a stray "\r" when "eol='\r\n'" by stripping the full eol string instead of one character.
-
gh-145105: Fix crash in "csv" reader when iterating with a re- entrant iterator that calls "next()" on the same reader from within "next".
-
gh-105936: Attempting to mutate non-field attributes of "dataclasses" with both frozen and slots being "True" now raises "FrozenInstanceError" instead of "TypeError". Their non-dataclass subclasses can now freely mutate non-field attributes, and the original non-slotted class can be garbage collected.
-
gh-140287: The "asyncio" REPL now handles exceptions when executing "PYTHONSTARTUP" scripts. Patch by Bartosz Sławecki.
-
gh-132631: Fix "I/O operation on closed file" when parsing JSON Lines file with "JSON CLI".
-
gh-70039: Fixed bug where "smtplib.SMTP.starttls()" could fail if "smtplib.SMTP.connect()" is called explicitly rather than implicitly.
-
gh-83281: "email": improve handling trailing garbage in address lists to avoid throwing AttributeError in certain edge cases
Documentation#
-
gh-148663: Document that "calendar.IllegalMonthError" is a subclass of both "ValueError" and "IndexError" since Python 3.12.
-
gh-146646: Document that "glob.glob()", "glob.iglob()", "pathlib.Path.glob()", and "pathlib.Path.rglob()" silently suppress "OSError" exceptions raised from scanning the filesystem.
Build#
-
gh-149351: Avoid possible broken macOS framework install names when DESTDIR is specified during builds.
-
gh-146475: Block Apple Clang from being used to build the JIT as it ships without required LLVM tools.
-
gh-148535: No longer use the "gcc -fprofile-update=atomic" flag on i686. The flag has been added to fix a random GCC internal error on PGO build (gh-145801) caused by corruption of profile data (.gcda files). The problem is that it makes the PGO build way slower (up to 47x slower) on i686. Since the GCC internal error was not seen on i686 so far, don't use "-fprofile-update=atomic" on i686 anymore. Patch by Victor Stinner.
-
gh-146264: Fix static module builds on non-WASI targets by linking HACL dependencies as static libraries when "MODULE_BUILDTYPE=static", preventing duplicate "Py_LibHacl*" symbol errors at link time.
Windows#
-
gh-149254: Updated bundled version of OpenSSL to 3.0.20.
-
gh-146458: Fix incorrect REPL height and width tracking on console window resize on Windows.
macOS#
- gh-149254: Update macOS installer to use OpenSSL 3.0.20.
Python 3.14.4 final#
Release date: 2026-04-07
Security#
-
gh-145986: "xml.parsers.expat": Fixed a crash caused by unbounded C recursion when converting deeply nested XML content models with "ElementDeclHandler()". This addresses CVE 2026-4224.
-
gh-145599: Reject control characters in "http.cookies.Morsel" "update()" and "js_output()". This addresses CVE 2026-3644.
-
gh-145506: Fixes CVE 2026-2297 by ensuring that "SourcelessFileLoader" uses "io.open_code()" when opening ".pyc" files.
-
gh-144370: Disallow usage of control characters in status in "wsgiref.handlers" to prevent HTTP header injections. Patch by Benedikt Johannes.
-
gh-143930: Reject leading dashes in URLs passed to "webbrowser.open()".
Core and Builtins#
-
gh-148157: Fix an unlikely crash when parsing an invalid type comments for function parameters. Found by OSS Fuzz in #492782951.
-
gh-148144: Initialize "_PyInterpreterFrame.visited" when copying interpreter frames so incremental GC does not read an uninitialized byte from generator and frame-object copies.
-
gh-146615: Fix a crash in "get()" for METH_METHOD descriptors when an invalid (non-type) object is passed as the second argument. Patch by Steven Sun.
-
gh-146308: Fixed several error handling issues in the "_remote_debugging" module, including safer validation of remote "int" objects, clearer asyncio task chain failures, and cache cleanup fixes that avoid leaking or double-freeing metadata on allocation failure. Patch by Pablo Galindo.
-
gh-146128: Fix a bug which could cause constant values to be partially corrupted in AArch64 JIT code. This issue is theoretical, and hasn't actually been observed in unmodified Python interpreters.
-
gh-146250: Fixed a memory leak in "SyntaxError" when re-initializing it.
-
gh-146245: Fixed reference leaks in "socket" when audit hooks raise exceptions in "socket.getaddrinfo()" and "socket.sendto()".
-
gh-146196: Fix potential Undefined Behavior in "PyUnicodeWriter_WriteASCII()" by adding a zero-length check. Patch by Shamil Abdulaev.
-
gh-146227: Fix wrong type in "_Py_atomic_load_uint16" in the C11 atomics backend ("pyatomic_std.h"), which used a 32-bit atomic load instead of 16-bit. Found by Mohammed Zuhaib.
-
gh-146056: Fix "repr()" for lists and tuples containing "NULL"s.
-
gh-146092: Handle properly memory allocation failures on str and float opcodes. Patch by Victor Stinner.
-
gh-146041: Fix free-threading scaling bottleneck in "sys.intern()" and "PyObject_SetAttr()" by avoiding the interpreter-wide lock when the string is already interned and immortalized.
-
gh-145990: "python --help-env" sections are now sorted by environment variable name.
-
gh-145990: "python --help-xoptions" is now sorted by "-X" option name.
-
gh-145376: Fix GC tracking in "structseq.replace()".
-
gh-145792: Fix out-of-bounds access when invoking faulthandler on a CPython build compiled without support for VLAs.
-
gh-142183: Avoid a pathological case where repeated calls at a specific stack depth could be significantly slower.
-
gh-145779: Improve scaling of "classmethod()" and "staticmethod()" calls in the free-threaded build by avoiding the descriptor "get" call.
-
gh-145783: Fix an unlikely crash in the parser when certain errors were erroneously not propagated. Found by OSS Fuzz in #491369109.
-
gh-145685: Improve scaling of type attribute lookups in the free- threaded build by avoiding contention on the internal type lock.
-
gh-145701: Fix "SystemError" when "classdict" or "conditional_annotations" is in a class-scope inlined comprehension. Found by OSS Fuzz in #491105000.
-
gh-145713: Make "bytearray.resize()" thread-safe in the free- threaded build by using a critical section and calling the lock-held variant of the resize function.
-
gh-145615: Fixed a memory leak in the free-threaded build where mimalloc pages could become permanently unreclaimable until the owning thread exited.
-
gh-145566: In the free threading build, skip the stop-the-world pause when reassigning "class" on a newly created object.
-
gh-145335: Fix a crash in "os.pathconf()" when called with "-1" as the path argument.
-
gh-145036: In free-threaded build, fix race condition when calling "sizeof()" on a "list"
-
gh-145376: Fix reference leaks in various unusual error scenarios.
-
gh-145234: Fixed a "SystemError" in the parser when an encoding cookie (for example, UTF-7) decodes to carriage returns ("\r"). Newlines are now normalized after decoding in the string tokenizer.
Patch by Pablo Galindo.
-
gh-130555: Fix use-after-free in "dict.clear()" when the dictionary values are embedded in an object and a destructor causes re-entrant mutation of the dictionary.
-
gh-145187: Fix compiler assertion fail when a type parameter bound contains an invalid expression in a conditional block.
-
gh-145142: Fix a crash in the free-threaded build when the dictionary argument to "str.maketrans()" is concurrently modified.
-
gh-144872: Fix heap buffer overflow in the parser found by OSS-Fuzz.
-
gh-144766: Fix a crash in fork child process when perf support is enabled.
-
gh-144759: Fix undefined behavior in the lexer when "start" and "multi_line_start" pointers are "NULL" in "_PyLexer_remember_fstring_buffers()" and "_PyLexer_restore_fstring_buffers()". The "NULL" pointer arithmetic ("NULL - valid_pointer") is now guarded with explicit "NULL" checks.
-
gh-144563: Fix interaction of the Tachyon profiler and "ctypes" and other modules that load the Python shared library (if present) in an independent map as this was causing the mechanism that loads the binary information to be confused. Patch by Pablo Galindo
-
gh-144601: Fix crash when importing a module whose "PyInit" function raises an exception from a subinterpreter.
-
gh-144438: Align the QSBR thread state array to a 64-byte cache line boundary to avoid false sharing in the free-threaded build.
-
gh-144513: Fix potential deadlock when using critical sections during stop-the-world pauses in the free-threaded build.
-
gh-144446: Fix data races in the free-threaded build when reading frame object attributes while another thread is executing the frame.
-
gh-143636: Fix a crash when calling "SimpleNamespace.replace()" on non-namespace instances. Patch by Bénédikt Tran.
-
gh-143650: Fix race condition in "importlib" where a thread could receive a stale module reference when another thread's import fails.
-
gh-141732: Ensure the "repr()" for "ExceptionGroup" and "BaseExceptionGroup" does not change when the exception sequence that was original passed in to its constructor is subsequently mutated.
-
gh-140594: Fix an out of bounds read when a single NUL character is read from the standard input. Patch by Shamil Abdulaev.
-
gh-91636: While performing garbage collection, clear weakrefs to unreachable objects that are created during running of finalizers. If those weakrefs were are not cleared, they could reveal unreachable objects.
-
gh-130327: Fix erroneous clearing of an object's "dict" if overwritten at runtime.
-
gh-80667: Literals using the "\N{name}" escape syntax can now construct CJK ideographs and Hangul syllables using case-insensitive names.
Library#
-
gh-144503: Fix a regression introduced in 3.14.3 and 3.13.12 where the "multiprocessing" "forkserver" start method would fail with "BrokenPipeError" when the parent process had a very large "sys.argv". The argv is now passed to the forkserver as separate command-line arguments rather than being embedded in the "-c" command string, avoiding the operating system's per-argument length limit.
-
gh-146613: "itertools": Fix a crash in "itertools.groupby()" when the grouper iterator is concurrently mutated.
-
gh-146080: "ssl": fix a crash when an SNI callback tries to use an SSL object that has already been garbage-collected. Patch by Bénédikt Tran.
-
gh-146556: Fix "annotationlib.get_annotations()" hanging indefinitely when called with "eval_str=True" on a callable that has a circular "wrapped" chain (e.g. "f.wrapped = f"). Cycle detection using an id-based visited set now stops the traversal and falls back to the globals found so far, mirroring the approach of "inspect.unwrap()".
-
gh-146090: "sqlite3": fix a crash when "sqlite3.Connection.create_collation()" fails with SQLITE_BUSY. Patch by Bénédikt Tran.
-
gh-146090: "sqlite3": properly raise "MemoryError" instead of "SystemError" when a context callback fails to be allocated. Patch by Bénédikt Tran.
-
gh-145633: Fix "struct.pack('f', float)": use "PyFloat_Pack4()" to raise "OverflowError". Patch by Sergey B Kirpichev and Victor Stinner.
-
gh-146310: The "ensurepip" module no longer looks for "pip-*.whl" wheel packages in the current directory.
-
gh-146083: Update bundled libexpat to version 2.7.5.
-
gh-146076: "zoneinfo": fix crashes when deleting "_weak_cache" from a "zoneinfo.ZoneInfo" subclass.
-
gh-146054: Limit the size of "encodings.search_function()" cache. Found by OSS Fuzz in #493449985.
-
gh-146004: All "-X" options from the Python command line are now propagated to child processes spawned by "multiprocessing", not just a hard-coded subset. This makes the behavior consistent between default "spawn" and "forkserver" start methods and the old "fork" start method. The options that were previously not propagated are: "context_aware_warnings", "cpu_count", "disable-remote-debug", "int_max_str_digits", "lazy_imports", "no_debug_ranges", "pathconfig_warnings", "perf", "perf_jit", "presite", "pycache_prefix", "thread_inherit_context", and "warn_default_encoding".
-
gh-145883: "zoneinfo": Fix heap buffer overflow reads from malformed TZif data. Found by OSS Fuzz, issues #492245058 and #492230068.
-
gh-145754: Request signature during mock autospec with "FORWARDREF" annotation format. This prevents runtime errors when an annotation uses a name that is not defined at runtime.
-
gh-145750: Avoid undefined behaviour from signed integer overflow when parsing format strings in the "struct" module. Found by OSS Fuzz in #488466741.
-
gh-145492: Fix infinite recursion in "collections.defaultdict" "repr" when a "defaultdict" contains itself. Based on analysis by KowalskiThomas in gh-145492.
-
gh-145623: Fix crash in "struct" when calling "repr()" or "sizeof()" on an uninitialized "struct.Struct" object created via "Struct.new()" without calling "init()".
-
gh-145616: Detect Android sysconfig ABI correctly on 32-bit ARM Android on 64-bit ARM kernel
-
gh-145551: Fix InvalidStateError when cancelling process created by "asyncio.create_subprocess_exec()" or "asyncio.create_subprocess_shell()". Patch by Daan De Meyer.
-
gh-145446: Now "functools" is safer in free-threaded build when using keywords in "functools.partial()"
-
gh-145417: "venv": Prevent incorrect preservation of SELinux context when copying the "Activate.ps1" script. The script inherited the SELinux security context of the system template directory, rather than the destination project directory.
-
gh-145376: Fix double free and null pointer dereference in unusual error scenarios in "hashlib" and "hmac" modules.
-
gh-145301: "hmac": fix a crash when the initialization of the underlying C extension module fails.
-
gh-145301: "hashlib": fix a crash when the initialization of the underlying C extension module fails.
-
gh-145264: Base64 decoder (see "binascii.a2b_base64()", "base64.b64decode()", etc) no longer ignores excess data after the first padded quad in non-strict (default) mode. Instead, in conformance with RFC 4648, section 3.3, it now ignores the pad character, "=", if it is present before the end of the encoded data.
-
gh-145158: Avoid undefined behaviour from signed integer overflow when parsing format strings in the "struct" module.
-
gh-144984: Fix crash in "xml.parsers.expat.xmlparser.ExternalEntityParserCreate()" when an allocation fails. The error paths could dereference NULL "handlers" and double-decrement the parent parser's reference count.
-
gh-88091: Fix "unicodedata.decomposition()" for Hangul characters.
-
gh-144986: Fix a memory leak in "atexit.register()". Patch by Shamil Abdulaev.
-
gh-144777: Fix data races in "io.IncrementalNewlineDecoder" in the free-threaded build.
-
gh-144809: Make "collections.deque" copy atomic in the free- threaded build.
-
gh-144835: Added missing explanations for some parameters in "glob.glob()" and "glob.iglob()".
-
gh-144833: Fixed a use-after-free in "ssl" when "SSL_new()" returns NULL in "newPySSLSocket()". The error was reported via a dangling pointer after the object had already been freed.
-
gh-144782: Fix "argparse.ArgumentParser" to be "pickleable".
-
gh-144259: Fix inconsistent display of long multiline pasted content in the REPL.
-
gh-144156: Fix the folding of headers by the "email" library when RFC 2047 encoded words are used. Now whitespace is correctly preserved and also correctly added between adjacent encoded words. The latter property was broken by the fix for gh-92081, which mostly fixed previous failures to preserve whitespace.
-
gh-66305: Fixed a hang on Windows in the "tempfile" module when trying to create a temporary file or subdirectory in a non-writable directory.
-
gh-140814: "multiprocessing.freeze_support()" no longer sets the default start method as a side effect, which previously caused a subsequent "multiprocessing.set_start_method()" call to raise "RuntimeError".
-
gh-144475: Calling "repr()" on "functools.partial()" is now safer when the partial object's internal attributes are replaced while the string representation is being generated.
-
gh-144538: Bump the version of pip bundled in ensurepip to version 26.0.1
-
gh-144494: Fix performance regression in "asyncio.all_tasks()" on free-threaded builds. Patch by Kumar Aditya.
-
gh-144316: Fix crash in "_remote_debugging" that caused "test_external_inspection" to intermittently fail. Patch by Taegyun Kim.
-
gh-144363: Update bundled libexpat to 2.7.4
-
gh-143637: Fixed a crash in socket.sendmsg() that could occur if ancillary data is mutated re-entrantly during argument parsing.
-
gh-143543: Fix a crash in itertools.groupby that could occur when a user-defined "eq()" method re-enters the iterator during key comparison.
-
gh-140652: Fix a crash in "_interpchannels.list_all()" after closing a channel.
-
gh-143698: Allow scheduler and setpgroup arguments to be explicitly "None" when calling "os.posix_spawn()" or "os.posix_spawnp()". Patch by Bénédikt Tran.
-
gh-143698: Raise "TypeError" instead of "SystemError" when the scheduler in "os.posix_spawn()" or "os.posix_spawnp()" is not a tuple. Patch by Bénédikt Tran.
-
gh-142516: "ssl": fix reference leaks in "ssl.SSLContext" objects. Patch by Bénédikt Tran.
-
gh-143304: Fix "ctypes.CDLL" to honor the "handle" parameter on POSIX systems.
-
gh-142781: "zoneinfo": fix a crash when instantiating "ZoneInfo" objects for which the internal class-level cache is inconsistent.
-
gh-142763: Fix a race condition between "zoneinfo.ZoneInfo" creation and "zoneinfo.ZoneInfo.clear_cache()" that could raise "KeyError".
-
gh-142787: Fix assertion failure in "sqlite3" blob subscript when slicing with indices that result in an empty slice.
-
gh-142352: Fix "asyncio.StreamWriter.start_tls()" to transfer buffered data from "StreamReader" to the SSL layer, preventing data loss when upgrading a connection to TLS mid-stream (e.g., when implementing PROXY protocol support).
-
gh-141707: Don't change "tarfile.TarInfo" type from "AREGTYPE" to "DIRTYPE" when parsing GNU long name or link headers.
-
gh-139933: Improve "AttributeError" suggestions for classes with a custom "dir()" method returning a list of unsortable values. Patch by Bénédikt Tran.
-
gh-137335: Get rid of any possibility of a name conflict for named pipes in "multiprocessing" and "asyncio" on Windows, no matter how small.
-
gh-80667: Support lookup for Tangut Ideographs in "unicodedata".
-
bpo-40243: Fix "unicodedata.ucd_3_2_0.numeric()" for non-decimal values.
Documentation#
-
gh-126676: Expand "argparse" documentation for "type=bool" with a demonstration of the surprising behavior and pointers to common alternatives.
-
gh-145649: Fix text wrapping and formatting of "-X" option descriptions in the python(1) man page by using proper roff markup.
-
gh-145450: Document missing public "wave.Wave_write" getter methods.
-
gh-136246: A new "Improve this page" link is available in the left- hand sidebar of the docs, offering links to create GitHub issues, discussion forum posts, or pull requests.
Tests#
-
gh-144418: The Android testbed's emulator RAM has been increased from 2 GB to 4 GB.
-
gh-146202: Fix a race condition in regrtest: make sure that the temporary directory is created in the worker process. Previously, temp_cwd() could fail on Windows if the "build" directory was not created. Patch by Victor Stinner.
-
gh-144739: When Python was compiled with system expat older then 2.7.2 but tests run with newer expat, still skip "test.test_pyexpat.MemoryProtectionTest".
Build#
-
gh-146541: The Android testbed can now be built for 32-bit ARM and x86 targets.
-
gh-146498: The iOS XCframework build script now ensures libpython isn't included in installed app content, and is more robust in identifying standard library binary content that requires processing.
-
gh-146450: The Android build script was modified to improve parity with other platform build scripts.
-
gh-146446: The clean target for the Apple/iOS XCframework build script is now more selective when targeting a single architecture.
-
gh-145801: When Python build is optimized with GCC using PGO, use "-fprofile-update=atomic" option to use atomic operations when updating profile information. This option reduces the risk of gcov Data Files (.gcda) corruption which can cause random GCC crashes. Patch by Victor Stinner.
Windows#
-
gh-145307: Defers loading of the "psapi.dll" module until it is used by "ctypes.util.dllist()".
-
gh-144551: Updated bundled version of OpenSSL to 3.0.19.
-
gh-140131: Fix REPL cursor position on Windows when module completion suggestion line hits console width.
macOS#
-
gh-144551: Update macOS installer to use OpenSSL 3.0.19.
-
gh-137586: Invoke osascript with absolute path in "webbrowser" and "turtledemo".
C API#
-
gh-146056: "PyUnicodeWriter_WriteRepr()" now supports "NULL" argument.
-
gh-145010: Use GCC dialect alternatives for inline assembly in "object.h" so that the Python headers compile correctly with "-masm=intel".
-
gh-144981: Made "PyUnstable_Code_SetExtra()", "PyUnstable_Code_GetExtra()", and "PyUnstable_Eval_RequestCodeExtraIndex()" thread-safe on the free threaded build.
Python 3.14.3 final#
Release date: 2026-02-03
Windows#
- gh-128067: Fix a bug in PyREPL on Windows where output without a trailing newline was overwritten by the next prompt.
Tools/Demos#
- gh-142095: Make gdb 'py-bt' command use frame from thread local state when available. Patch by Sam Gross and Victor Stinner.
Tests#
-
gh-144415: The Android testbed now distinguishes between stdout/stderr messages which were triggered by a newline, and those triggered by a manual call to "flush". This fixes logging of progress indicators and similar content.
-
gh-143460: Skip tests relying on infinite recusion if stack size is unlimited.
-
gh-65784: Add support for parametrized resource "wantobjects" in regrtests, which allows to run Tkinter tests with the specified value of "tkinter.wantobjects", for example "-u wantobjects=0".
-
gh-143553: Add support for parametrized resources, such as "-u xpickle=2.7".
-
gh-142836: Accommodated Solaris in "test_pdb.test_script_target_anonymous_pipe".
-
bpo-31391: Forward-port test_xpickle from Python 2 to Python 3 and add the resource back to test's command line.
Security#
-
gh-144125: "BytesGenerator" will now refuse to serialize (write) headers that are unsafely folded or delimited; see "verify_generated_headers". (Contributed by Bas Bloemsaat and Petr Viktorin in gh-121650).
-
gh-143935: Fixed a bug in the folding of comments when flattening an email message using a modern email policy. Comments consisting of a very long sequence of non-foldable characters could trigger a forced line wrap that omitted the required leading space on the continuation line, causing the remainder of the comment to be interpreted as a new header field. This enabled header injection with carefully crafted inputs.
-
gh-143925: Reject control characters in "data:" URL media types.
-
gh-143919: Reject control characters in "http.cookies.Morsel" fields and values.
-
gh-143916: Reject C0 control characters within wsgiref.headers.Headers fields, values, and parameters.
Library#
-
gh-144380: Improve performance of "io.BufferedReader" line iteration by ~49%.
-
gh-144169: Fix three crashes when non-string keyword arguments are supplied to objects in the "ast" module.
-
gh-144100: Fixed a crash in ctypes when using a deprecated "POINTER(str)" type in "argtypes". Instead of aborting, ctypes now raises a proper Python exception when the pointer target type is unresolved.
-
gh-144050: Fix "stat.filemode()" in the pure-Python implementation to avoid misclassifying invalid mode values as block devices.
-
gh-144023: Fixed validation of file descriptor 0 in posix functions when used with follow_symlinks parameter.
-
gh-143999: Fix an issue where "inspect.getgeneratorstate()" and "inspect.getcoroutinestate()" could fail for generators wrapped by "types.coroutine()" in the suspended state.
-
gh-143831: "annotationlib.ForwardRef" objects are now hashable when created from annotation scopes with closures. Previously, hashing such objects would throw an exception. Patch by Bartosz Sławecki.
-
gh-143874: Fixed a bug in "pdb" where expression results were not sent back to remote client.
-
gh-143880: Fix data race in "functools.partial()" in the free threading build.
-
gh-143706: Fix "multiprocessing" forkserver so that "sys.argv" is correctly set before "main" is preloaded. Previously, "sys.argv" was empty during main module import in forkserver child processes. This fixes a regression introduced in 3.13.8 and 3.14.1. Root caused by Aaron Wieczorek, test provided by Thomas Watson, thanks!
-
gh-143638: Forbid reentrant calls of the "pickle.Pickler" and "pickle.Unpickler" methods for the C implementation. Previously, this could cause crash or data corruption, now concurrent calls of methods of the same object raise "RuntimeError".
-
gh-78724: Raise "RuntimeError"'s when user attempts to call methods on half-initialized "Struct" objects, For example, created by "Struct.new(Struct)". Patch by Sergey B Kirpichev.
-
gh-143196: Fix crash when the internal encoder object returned by undocumented function "json.encoder.c_make_encoder()" was called with non-zero second (_current_indent_level) argument.
-
gh-143191: "_thread.stack_size()" now raises "ValueError" if the stack size is too small. Patch by Victor Stinner.
-
gh-143602: Fix a inconsistency issue in "write()" that leads to unexpected buffer overwrite by deduplicating the buffer exports.
-
gh-143547: Fix "sys.unraisablehook()" when the hook raises an exception and changes "sys.unraisablehook()": hold a strong reference to the old hook. Patch by Victor Stinner.
-
gh-143517: "annotationlib.get_annotations()" no longer raises a "SyntaxError" when evaluating a stringified starred annotation that starts with one or more whitespace characters followed by a "*". Patch by Bartosz Sławecki.
-
gh-143378: Fix use-after-free crashes when a "BytesIO" object is concurrently mutated during "write()" or "writelines()".
-
gh-143346: Fix incorrect wrapping of the Base64 data in "plistlib._PlistWriter" when the indent contains a mix of tabs and spaces.
-
gh-143310: "tkinter": fix a crash when a Python "list" is mutated during the conversion to a Tcl object (e.g., when setting a Tcl variable). Patch by Bénédikt Tran.
-
gh-143309: Fix a crash in "os.execve()" on non-Windows platforms when given a custom environment mapping which is then mutated during parsing. Patch by Bénédikt Tran.
-
gh-143308: "pickle": fix use-after-free crashes when a "PickleBuffer" is concurrently mutated by a custom buffer callback during pickling. Patch by Bénédikt Tran and Aaron Wieczorek.
-
gh-143237: Fix support of named pipes in the rotating "logging" handlers.
-
gh-143249: Fix possible buffer leaks in Windows overlapped I/O on error handling.
-
gh-143241: "zoneinfo": fix infinite loop in "ZoneInfo.from_file" when parsing a malformed TZif file. Patch by Fatih Celik.
-
gh-142830: "sqlite3": fix use-after-free crashes when the connection's callbacks are mutated during a callback execution. Patch by Bénédikt Tran.
-
gh-143200: "xml.etree.ElementTree": fix use-after-free crashes in "getitem()" and "setitem()" methods of "Element" when the element is concurrently mutated. Patch by Bénédikt Tran.
-
gh-142195: Updated timeout evaluation logic in "subprocess" to be compatible with deterministic environments like Shadow where time moves exactly as requested.
-
gh-142164: Fix the ctypes bitfield overflow error message to report the correct offset and size calculation.
-
gh-143145: Fixed a possible reference leak in ctypes when constructing results with multiple output parameters on error.
-
gh-122431: Corrected the error message in "readline.append_history_file()" to state that "nelements" must be non-negative instead of positive.
-
gh-143004: Fix a potential use-after-free in "collections.Counter.update()" when user code mutates the Counter during an update.
-
gh-143046: The "asyncio" REPL no longer prints copyright and version messages in the quiet mode ("-q"). Patch by Bartosz Sławecki.
-
gh-140648: The "asyncio" REPL now respects the "-I" flag (isolated mode). Previously, it would load and execute "PYTHONSTARTUP" even if the flag was set. Contributed by Bartosz Sławecki.
-
gh-142991: Fixed socket operations such as recvfrom() and sendto() for FreeBSD divert(4) socket.
-
gh-143010: Fixed a bug in "mailbox" where the precise timing of an external event could result in the library opening an existing file instead of a file it expected to create.
-
gh-142881: Fix concurrent and reentrant call of "atexit.unregister()".
-
gh-112127: Fix possible use-after-free in "atexit.unregister()" when the callback is unregistered during comparison.
-
gh-142783: Fix zoneinfo use-after-free with descriptor _weak_cache. a descriptor as _weak_cache could cause crashes during object creation. The fix ensures proper reference counting for descriptor- provided objects.
-
gh-142754: Add the ownerDocument attribute to "xml.dom.minidom" elements and attributes created by directly instantiating the "Element" or "Attr" class. Note that this way of creating nodes is not supported; creator functions like "xml.dom.Document.documentElement()" should be used instead.
-
gh-142784: The "asyncio" REPL now properly closes the loop upon the end of interactive session. Previously, it could cause surprising warnings. Contributed by Bartosz Sławecki.
-
gh-142555: "array": fix a crash in "a[i] = v" when converting i to an index via "i.index" or "i.float" mutates the array.
-
gh-142594: Fix crash in "TextIOWrapper.close()" when the underlying buffer's "closed" property calls "detach()".
-
gh-142451: "hmac": Ensure that the "HMAC.block_size" attribute is correctly copied by "HMAC.copy". Patch by Bénédikt Tran.
-
gh-142495: "collections.defaultdict" now prioritizes "setitem()" when inserting default values from "default_factory". This prevents race conditions where a default value would overwrite a value set before "default_factory" returns.
-
gh-142651: "unittest.mock": fix a thread safety issue where "Mock.call_count" may return inaccurate values when the mock is called concurrently from multiple threads.
-
gh-142595: Added type check during initialization of the "decimal" module to prevent a crash in case of broken stdlib. Patch by Sergey B Kirpichev.
-
gh-142556: Fix crash when a task gets re-registered during finalization in "asyncio". Patch by Kumar Aditya.
-
gh-123241: Avoid reference count operations in garbage collection of "ctypes" objects.
-
gh-142517: The non-"compat32" "email" policies now correctly handle refolding encoded words that contain bytes that can not be decoded in their specified character set. Previously this resulted in an encoding exception during folding.
-
gh-112527: The help text for required options in "argparse" no longer extended with " (default: None)".
-
gh-142346: Fix usage formatting for mutually exclusive groups in "argparse" when they are preceded by positional arguments or followed or intermixed with other optional arguments.
-
gh-142315: Pdb can now run scripts from anonymous pipes used in process substitution. Patch by Bartosz Sławecki.
-
gh-142332: Fix usage formatting for positional arguments in mutually exclusive groups in "argparse". in "argparse".
-
gh-142282: Fix "winreg.QueryValueEx()" to not accidentally read garbage buffer under race condition.
-
gh-75949: Fix "argparse" to preserve "|" separators in mutually exclusive groups when the usage line wraps due to length.
-
gh-142267: Improve "argparse" performance by caching the formatter used for argument validation.
-
gh-68552: "MisplacedEnvelopeHeaderDefect" and "Missing header name" defects are now correctly passed to the "handle_defect" method of "policy" in "FeedParser".
-
gh-142006: Fix a bug in the "email.policy.default" folding algorithm which incorrectly resulted in a doubled newline when a line ending at exactly max_line_length was followed by an unfoldable token.
-
gh-105836: Fix "asyncio.run_coroutine_threadsafe()" leaving underlying cancelled asyncio task running.
-
gh-139971: "pydoc": Ensure that the link to the online documentation of a stdlib module is correct.
-
gh-139262: Some keystrokes can be swallowed in the new "PyREPL" on Windows, especially when used together with the ALT key. Fix by Chris Eibl.
-
gh-138897: Improved "license"/"copyright"/"credits" display in the REPL: now uses a pager.
-
gh-79986: Add parsing for "References" and "In-Reply-To" headers to the "email" library that parses the header content as lists of message id tokens. This prevents them from being folded incorrectly.
-
gh-136282: Add support for "UNNAMED_SECTION" when creating a section via the mapping protocol access
-
gh-109263: Starting a process from spawn context in "multiprocessing" no longer sets the start method globally.
-
gh-133253: Fix thread-safety issues in "linecache".
-
gh-132715: Skip writing objects during marshalling once a failure has occurred.
IDLE#
- gh-143774: Better explain the operation of Format / Format Paragraph.
Documentation#
- gh-140806: Add documentation for "enum.bin()".
Core and Builtins#
-
gh-144307: Prevent a reference leak in module teardown at interpreter finalization.
-
gh-144194: Fix error handling in perf jitdump initialization on memory allocation failure.
-
gh-144012: Check if the result is "NULL" in "BINARY_OP_EXTENT" opcode.
-
gh-141805: Fix crash in "set" when objects with the same hash are concurrently added to the set after removing an element with the same hash while the set still contains elements with the same hash.
-
gh-143670: Fixes a crash in "ga_repr_items_list" function.
-
gh-143377: Fix a crash in "_interpreters.capture_exception()" when the exception is incorrectly formatted. Patch by Bénédikt Tran.
-
gh-136924: The interactive help mode in the REPL no longer incorrectly syntax highlights text input as Python code. Contributed by Olga Matoula.
-
gh-143189: Fix crash when inserting a non-"str" key into a split table dictionary when the key matches an existing key in the split table but has no corresponding value in the dict.
-
gh-143228: Fix use-after-free in perf trampoline when toggling profiling while threads are running or during interpreter finalization with daemon threads active. The fix uses reference counting to ensure trampolines are not freed while any code object could still reference them. Pach by Pablo Galindo
-
gh-142664: Fix a use-after-free crash in "memoryview.hash" when the "hash" method of the referenced object mutates that object or the view. Patch by Bénédikt Tran.
-
gh-142557: Fix a use-after-free crash in bytearray.mod when the "bytearray" is mutated while formatting the "%"-style arguments. Patch by Bénédikt Tran.
-
gh-143195: Fix use-after-free crashes in "bytearray.hex()" and "memoryview.hex()" when the separator's "len()" mutates the original object. Patch by Bénédikt Tran.
-
gh-142975: Fix crash after unfreezing all objects tracked by the garbage collector on the free threaded build.
-
gh-143135: Set "sys.flags.inspect" to "1" when "PYTHONINSPECT" is "0". Previously, it was set to "0" in this case.
-
gh-143003: Fix an overflow of the shared empty buffer in "bytearray.extend()" when "length_hint()" returns 0 for non- empty iterator.
-
gh-143006: Fix a possible assertion error when comparing negative non-integer "float" and "int" with the same number of bits in the integer part.
-
gh-143057: Avoid locking in "PyTraceMalloc_Track()" and "PyTraceMalloc_Untrack()" when "tracemalloc" is not enabled.
-
gh-142776: Fix a file descriptor leak in import.c
-
gh-142829: Fix a use-after-free crash in "contextvars.Context" comparison when a custom "eq" method modifies the context via "set()".
-
gh-142766: Clear the frame of a generator when "generator.close()" is called.
-
gh-142737: Tracebacks will be displayed in fallback mode even if "io.open()" is lost. Previously, this would crash the interpreter. Patch by Bartosz Sławecki.
-
gh-142554: Fix a crash in "divmod()" when "_pylong.int_divmod()" does not return a tuple of length two exactly. Patch by Bénédikt Tran.
-
gh-142560: Fix use-after-free in "bytearray" search-like methods ("find()", "count()", "index()", "rindex()", and "rfind()") by marking the storage as exported which causes reallocation attempts to raise "BufferError". For "contains()", "split()", and "rsplit()" the buffer protocol is used for this.
-
gh-142531: Fix a free-threaded GC performance regression. If there are many untracked tuples, the GC will run too often, resulting in poor performance. The fix is to include untracked tuples in the "long lived" object count. The number of frozen objects is also now included since the free-threaded GC must scan those too.
-
gh-142402: Fix reference counting when adjacent literal parts are merged while constructing "string.templatelib.Template", preventing the displaced string object from leaking.
-
gh-133932: Fix crash in the free threading build when clearing frames that hold tagged integers.
-
gh-142343: Fix SIGILL crash on m68k due to incorrect assembly constraint.
-
gh-100964: Fix reference cycle in exhausted generator frames. Patch by Savannah Ostrowski.
-
gh-69605: Fix edge-cases around already imported modules in the REPL auto-completion of imports.
-
gh-138568: Adjusted the built-in "help()" function so that empty inputs are ignored in interactive mode.
-
gh-137007: Fix a bug during JIT compilation failure which caused garbage collection debug assertions to fail.
C API#
-
gh-142589: Fix "PyUnstable_Object_IsUniqueReferencedTemporary()" handling of tagged ints on the interpreter stack.
-
gh-142571: "PyUnstable_CopyPerfMapFile()" now checks that opening the file succeeded before flushing.
Build#
-
gh-142454: When calculating the digest of the JIT stencils input, sort the hashed files by filenames before adding their content to the hasher. This ensures deterministic hash input and hence deterministic hash, independent on filesystem order.
-
gh-141808: When running "make clean-retain-profile", keep the generated JIT stencils. That way, the stencils are not generated twice when Profile-guided optimization (PGO) is used. It also allows distributors to supply their own pre-built JIT stencils.
-
gh-138061: Ensure reproducible builds by making JIT stencil header generation deterministic.
Python 3.14.2 final#
Release date: 2025-12-05
Security#
-
gh-142145: Remove quadratic behavior in "xml.minidom" node ID cache clearing.
-
gh-119452: Fix a potential memory denial of service in the "http.server" module. When a malicious user is connected to the CGI server on Windows, it could cause an arbitrary amount of memory to be allocated. This could have led to symptoms including a "MemoryError", swapping, out of memory (OOM) killed processes or containers, or even system crashes.
Library#
-
gh-140797: Revert changes to the undocumented "re.Scanner" class. Capturing groups are still allowed for backward compatibility, although using them can lead to incorrect result. They will be forbidden in future Python versions.
-
gh-142206: The resource tracker in the "multiprocessing" module now uses the original communication protocol, as in Python 3.14.0 and below, by default. This avoids issues with upgrading Python while it is running. (Note that such 'in-place' upgrades are not tested.) The tracker remains compatible with subprocesses that use new protocol (that is, subprocesses using Python 3.13.10, 3.14.1 and 3.15).
-
gh-142214: Fix two regressions in "dataclasses" in Python 3.14.1 related to annotations.
-
An exception is no longer raised if "slots=True" is used and the "init" method does not have an "annotate" attribute (likely because "init=False" was used).
-
An exception is no longer raised if annotations are requested on the "init" method and one of the fields is not present in the class annotations. This can occur in certain dynamic scenarios.
Patch by Jelle Zijlstra.
Core and Builtins#
- gh-142218: Fix crash when inserting into a split table dictionary with a non "str" key that matches an existing key.
Library#
- gh-116738: Fix "cmath" data race when initializing trigonometric tables with subinterpreters.
Python 3.14.1 final#
Release date: 2025-12-02
Windows#
- gh-139810: Installing with "py install 3[.x]-dev" will now select final versions as well as prereleases.
Tools/Demos#
-
gh-141692: Each slice of an iOS XCframework now contains a "lib" folder that contains a symlink to the libpython dylib. This allows binary modules to be compiled for iOS using dynamic libreary linking, rather than Framework linking.
-
gh-141442: The iOS testbed now correctly handles test arguments that contain spaces.
-
gh-140702: The iOS testbed app will now expose the "GITHUB_ACTIONS" environment variable to iOS apps being tested.
-
gh-137484: Have "Tools/wasm/wasi" put the build Python into a directory named after the build triple instead of "build".
-
gh-137248: Add a "--logdir" option to "Tools/wasm/wasi" for specifying where to write log files.
-
gh-137243: Have Tools/wasm/wasi detect a WASI SDK install in /opt when it was directly extracted from a release tarball.
Tests#
-
gh-140482: Preserve and restore the state of "stty echo" as part of the test environment.
-
gh-140082: Update "python -m test" to set "FORCE_COLOR=1" when being run with color enabled so that "unittest" which is run by it with redirected output will output in color.
-
gh-139208: Fix regrtest "--fast-ci --verbose": don't ignore the "-- verbose" option anymore. Patch by Victor Stinner.
-
gh-136442: Use exitcode "1" instead of "5" if "unittest.TestCase.setUpClass()" raises an exception
Security#
-
gh-139700: Check consistency of the zip64 end of central directory record. Support records with "zip64 extensible data" if there are no bytes prepended to the ZIP file.
-
gh-139283: "sqlite3": correctly handle maximum number of rows to fetch in "Cursor.fetchmany" and reject negative values for "Cursor.arraysize". Patch by Bénédikt Tran.
-
gh-137836: Add support of the "plaintext" element, RAWTEXT elements "xmp", "iframe", "noembed" and "noframes", and optionally RAWTEXT element "noscript" in "html.parser.HTMLParser".
-
gh-136063: "email.message": ensure linear complexity for legacy HTTP parameters parsing. Patch by Bénédikt Tran.
-
gh-136065: Fix quadratic complexity in "os.path.expandvars()".
-
gh-119451: Fix a potential memory denial of service in the "http.client" module. When connecting to a malicious server, it could cause an arbitrary amount of memory to be allocated. This could have led to symptoms including a "MemoryError", swapping, out of memory (OOM) killed processes or containers, or even system crashes.
-
gh-119342: Fix a potential memory denial of service in the "plistlib" module. When reading a Plist file received from untrusted source, it could cause an arbitrary amount of memory to be allocated. This could have led to symptoms including a "MemoryError", swapping, out of memory (OOM) killed processes or containers, or even system crashes.
Library#
-
gh-74389: When the stdin being used by a "subprocess.Popen" instance is closed, this is now ignored in "subprocess.Popen.communicate()" instead of leaving the class in an inconsistent state.
-
gh-87512: Fix "subprocess.Popen.communicate()" timeout handling on Windows when writing large input. Previously, the timeout was ignored during stdin writing, causing the method to block indefinitely if the child process did not consume input quickly. The stdin write is now performed in a background thread, allowing the timeout to be properly enforced.
-
gh-141473: When "subprocess.Popen.communicate()" was called with input and a timeout and is called for a second time after a "TimeoutExpired" exception before the process has died, it should no longer hang.
-
gh-59000: Fix "pdb" breakpoint resolution for class methods when the module defining the class is not imported.
-
gh-141570: Support file-like object raising "OSError" from "fileno()" in color detection ("_colorize.can_colorize()"). This can occur when "sys.stdout" is redirected.
-
gh-141659: Fix bad file descriptor errors from "_posixsubprocess" on AIX.
-
gh-141600: Fix musl version detection on Void Linux.
-
gh-141497: "ipaddress": ensure that the methods "IPv4Network.hosts()" and "IPv6Network.hosts()" always return an iterator.
-
gh-140938: The "statistics.stdev()" and "statistics.pstdev()" functions now raise a "ValueError" when the input contains an infinity or a NaN.
-
gh-124111: Updated Tcl threading configuration in "_tkinter" to assume that threads are always available in Tcl 9 and later.
-
gh-137109: The "os.fork" and related forking APIs will no longer warn in the common case where Linux or macOS platform APIs return the number of threads in a process and find the answer to be 1 even when a "os.register_at_fork()" "after_in_parent=" callback (re)starts a thread.
-
gh-141314: Fix assertion failure in "io.TextIOWrapper.tell()" when reading files with standalone carriage return ("\r") line endings.
-
gh-141311: Fix assertion failure in "io.BytesIO.readinto()" and undefined behavior arising when read position is above capcity in "io.BytesIO".
-
gh-141141: Fix a thread safety issue with "base64.b85decode()". Contributed by Benel Tayar.
-
gh-137969: Fix "annotationlib.ForwardRef.evaluate()" returning "ForwardRef" objects which don't update with new globals.
-
gh-140911: "collections": Ensure that the methods "UserString.rindex()" and "UserString.index()" accept "collections.UserString" instances as the sub argument.
-
gh-140797: The undocumented "re.Scanner" class now forbids regular expressions containing capturing groups in its lexicon patterns. Patterns using capturing groups could previously lead to crashes with segmentation fault. Use non-capturing groups (?:...) instead.
-
gh-125115: Refactor the "pdb" parsing issue so positional arguments can pass through intuitively.
-
gh-140815: "faulthandler" now detects if a frame or a code object is invalid or freed. Patch by Victor Stinner.
-
gh-100218: Correctly set "errno" when "socket.if_nametoindex()" or "socket.if_indextoname()" raise an "OSError". Patch by Bénédikt Tran.
-
gh-140875: Fix handling of unclosed character references (named and numerical) followed by the end of file in "html.parser.HTMLParser" with "convert_charrefs=False".
-
gh-140734: "multiprocessing": fix off-by-one error when checking the length of a temporary socket file path. Patch by Bénédikt Tran.
-
gh-140874: Bump the version of pip bundled in ensurepip to version 25.3
-
gh-140691: In "urllib.request", when opening a FTP URL fails because a data connection cannot be made, the control connection's socket is now closed to avoid a "ResourceWarning".
-
gh-103847: Fix hang when cancelling process created by "asyncio.create_subprocess_exec()" or "asyncio.create_subprocess_shell()". Patch by Kumar Aditya.
-
gh-120057: Add "os.reload_environ()" to "os.all".
-
gh-140228: Avoid making unnecessary filesystem calls for frozen modules in "linecache" when the global module cache is not present.
-
gh-140590: Fix arguments checking for the "functools.partial.setstate()" that may lead to internal state corruption and crash. Patch by Sergey Miryanov.
-
gh-125434: Display thread name in "faulthandler" on Windows. Patch by Victor Stinner.
-
gh-140634: Fix a reference counting bug in "os.sched_param.reduce()".
-
gh-140633: Ignore "AttributeError" when setting a module's "file" attribute when loading an extension module packaged as Apple Framework.
-
gh-140593: "xml.parsers.expat": Fix a memory leak that could affect users with "ElementDeclHandler()" set to a custom element declaration handler. Patch by Sebastian Pipping.
-
gh-140607: Inside "io.RawIOBase.read()", validate that the count of bytes returned by "io.RawIOBase.readinto()" is valid (inside the provided buffer).
-
gh-138162: Fix "logging.LoggerAdapter" with "merge_extra=True" and without the extra argument.
-
gh-138774: "ast.unparse()" now generates full source code when handling "ast.Interpolation" nodes that do not have a specified source.
-
gh-140474: Fix memory leak in "array.array" when creating arrays from an empty "str" and the "u" type code.
-
gh-137530: "dataclasses" Fix annotations for generated "init" methods by replacing the annotations that were in-line in the generated source code with "annotate" functions attached to the methods.
-
gh-140348: Fix regression in Python 3.14.0 where using the "|" operator on a "typing.Union" object combined with an object that is not a type would raise an error.
-
gh-140272: Fix memory leak in the "clear()" method of the "dbm.gnu" database.
-
gh-140041: Fix import of "ctypes" on Android and Cygwin when ABI flags are present.
-
gh-140120: Fixed a memory leak in "hmac" when it was using the hacl- star backend. Discovered by "@ashm-dev" using AddressSanitizer.
-
gh-139905: Add suggestion to error message for "typing.Generic" subclasses when "cls.parameters" is missing due to a parent class failing to call "super().init_subclass()" in its "init_subclass".
-
gh-139894: Fix incorrect sharing of current task with the child process while forking in "asyncio". Patch by Kumar Aditya.
-
gh-139845: Fix to not print KeyboardInterrupt twice in default asyncio REPL.
-
gh-139783: Fix "inspect.getsourcelines()" for the case when a decorator is followed by a comment or an empty line.
-
gh-139809: Prevent premature colorization of subparser "prog" in "argparse.ArgumentParser.add_subparsers()" to respect color environment variable changes after parser creation.
-
gh-139736: Fix excessive indentation in the default "argparse" "HelpFormatter". Patch by Alexander Edland.
-
gh-70765: "http.server": fix default handling of HTTP/0.9 requests in "BaseHTTPRequestHandler". Previously, "BaseHTTPRequestHandler.parse_request()" incorrectly waited for headers in the request although those are not supported in HTTP/0.9. Patch by Bénédikt Tran.
-
gh-63161: Fix "tokenize.detect_encoding()". Support non-UTF-8 shebang and comments if non-UTF-8 encoding is specified. Detect decoding error for non-UTF-8 encoding. Detect null bytes in source code.
-
gh-139391: Fix an issue when, on non-Windows platforms, it was not possible to gracefully exit a "python -m asyncio" process suspended by Ctrl+Z and later resumed by fg other than with kill.
-
gh-101828: Fix "'shift_jisx0213'", "'shift_jis_2004'", "'euc_jisx0213'" and "'euc_jis_2004'" codecs truncating null chars as they were treated as part of multi-character sequences.
-
gh-139289: Do a real lazy-import on "rlcompleter" in "pdb" and restore the existing completer after importing "rlcompleter".
-
gh-139246: fix: paste zero-width in default repl width is wrong.
-
gh-90949: Add "SetAllocTrackerActivationThreshold()" and "SetAllocTrackerMaximumAmplification()" to xmlparser objects to tune protections against disproportional amounts of dynamic memory usage from within an Expat parser. Patch by Bénédikt Tran.
-
gh-139210: Fix use-after-free when reporting unknown event in "xml.etree.ElementTree.iterparse()". Patch by Ken Jin.
-
gh-138860: Lazy import "rlcompleter" in "pdb" to avoid deadlock in subprocess.
-
gh-112729: Fix crash when calling "concurrent.interpreters.create()" when the process is out of memory.
-
gh-135729: Fix unraisable exception during finalization when using "concurrent.interpreters" in the REPL.
-
gh-139076: Fix a bug in the "pydoc" module that was hiding functions in a Python module if they were implemented in an extension module and the module did not have "all".
-
gh-139065: Fix trailing space before a wrapped long word if the line length is exactly width in "textwrap".
-
gh-139001: Fix race condition in "pathlib.Path" on the internal "_raw_paths" field.
-
gh-138813: "multiprocessing.BaseProcess" defaults "kwargs" to "None" instead of a shared dictionary.
-
gh-138993: Dedent "credits" text.
-
gh-138891: Fix "SyntaxError" when "inspect.get_annotations(f, eval_str=True)" is called on a function annotated with a PEP 646 "star_expression"
-
gh-130567: Fix possible crash in "locale.strxfrm()" due to a platform bug on macOS.
-
gh-138859: Fix generic type parameterization raising a "TypeError" when omitting a "ParamSpec" that has a default which is not a list of types.
-
gh-138764: Prevent "annotationlib.call_annotate_function()" from calling "annotate" functions that don't support "VALUE_WITH_FAKE_GLOBALS" in a fake globals namespace with empty globals.
Make "FORWARDREF" and "STRING" annotations fall back to using "VALUE" annotations in the case that neither their own format, nor "VALUE_WITH_FAKE_GLOBALS" are supported.
-
gh-138775: Use of "python -m" with "base64" has been fixed to detect input from a terminal so that it properly notices EOF.
-
gh-138779: Support device numbers larger than "2**63-1" for the "st_rdev" field of the "os.stat_result" structure.
-
gh-137706: Fix the partial evaluation of annotations that use "typing.Annotated[T, x]" where "T" is a forward reference.
-
gh-88375: Fix normalization of the "robots.txt" rules and URLs in the "urllib.robotparser" module. No longer ignore trailing "?". Distinguish raw special characters "?", "=" and "&" from the percent-encoded ones.
-
gh-111788: Fix parsing errors in the "urllib.robotparser" module. Don't fail trying to parse weird paths. Don't fail trying to decode non-UTF-8 "robots.txt" files.
-
gh-98896: Fix a failure in multiprocessing resource_tracker when SharedMemory names contain colons. Patch by Rani Pinchuk.
-
gh-138425: Fix partial evaluation of "annotationlib.ForwardRef" objects which rely on names defined as globals.
-
gh-138432: "zoneinfo.reset_tzpath()" will now convert any "os.PathLike" objects it receives into strings before adding them to "TZPATH". It will raise "TypeError" if anything other than a string is found after this conversion. If given an "os.PathLike" object that represents a relative path, it will now raise "ValueError" instead of "TypeError", and present a more informative error message.
-
gh-138008: Fix segmentation faults in the "ctypes" module due to invalid "argtypes". Patch by Dung Nguyen.
-
gh-60462: Fix "locale.strxfrm()" on Solaris (and possibly other platforms).
-
gh-138239: The REPL now highlights "type" as a soft keyword in type statements.
-
gh-138204: Forbid expansion of shared anonymous "memory maps" on Linux, which caused a bus error.
-
gh-138010: Fix an issue where defining a class with an "@warnings.deprecated"-decorated base class may not invoke the correct "init_subclass()" method in cases involving multiple inheritance. Patch by Brian Schubert.
-
gh-138151: In "annotationlib", improve evaluation of forward references to nonlocal variables that are not yet defined when the annotations are initially evaluated.
-
gh-137317: "inspect.signature()" now correctly handles classes that use a descriptor on a wrapped "init()" or "new()" method. Contributed by Yongyu Yan.
-
gh-137754: Fix import of the "zoneinfo" module if the C implementation of the "datetime" module is not available.
-
gh-137490: Handle "ECANCELED" in the same way as "EINTR" in "signal.sigwaitinfo()" on NetBSD.
-
gh-137477: Fix "inspect.getblock()", "inspect.getsourcelines()" and "inspect.getsource()" for generator expressions.
-
gh-137044: Return large limit values as positive integers instead of negative integers in "resource.getrlimit()". Accept large values and reject negative values (except "RLIM_INFINITY") for limits in "resource.setrlimit()".
-
gh-75989: "tarfile.TarFile.extractall()" and "tarfile.TarFile.extract()" now overwrite symlinks when extracting hardlinks. (Contributed by Alexander Enrique Urieles Nieto in gh-75989.)
-
gh-137017: Fix "threading.Thread.is_alive" to remain "True" until the underlying OS thread is fully cleaned up. This avoids false negatives in edge cases involving thread monitoring or premature "threading.Thread.is_alive" calls.
-
gh-137273: Fix debug assertion failure in "locale.setlocale()" on Windows.
-
gh-137239: "heapq": Update "heapq.all" with "*_max" functions.
-
gh-81325: "tarfile.TarFile" now accepts a path-like when working on a tar archive. (Contributed by Alexander Enrique Urieles Nieto in gh-81325.)
-
gh-137185: Fix a potential async-signal-safety issue in "faulthandler" when printing C stack traces.
-
gh-136914: Fix retrieval of "doctest.DocTest.lineno" for objects decorated with "functools.cache()" or "functools.cached_property".
-
gh-136912: "hmac.digest()" now properly handles large keys and messages by falling back to the pure Python implementation when necessary. Patch by Bénédikt Tran.
-
gh-83424: Allows creating a "ctypes.CDLL" without name when passing a handle as an argument.
-
gh-136234: Fix "asyncio.WriteTransport.writelines()" to be robust to connection failure, by using the same behavior as "write()".
-
gh-136507: Fix mimetypes CLI to handle multiple file parameters.
-
gh-136057: Fixed the bug in "pdb" and "bdb" where "next" and "step" can't go over the line if a loop exists in the line.
-
gh-135386: Fix opening a "dbm.sqlite3" database for reading from read-only file or directory.
-
gh-135444: Fix "asyncio.DatagramTransport.sendto()" to account for datagram header size when data cannot be sent.
-
gh-126631: Fix "multiprocessing" "forkserver" bug which prevented "main" from being preloaded.
-
gh-135307: "email": Fix exception in "set_content()" when encoding text and max_line_length is set to "0" or "None" (unlimited).
-
gh-134453: Fixed "subprocess.Popen.communicate()" "input=" handling of "memoryview" instances that were non-byte shaped on POSIX platforms. Those are now properly cast to a byte shaped view instead of truncating the input. Windows platforms did not have this bug.
-
gh-134698: Fix a crash when calling methods of "ssl.SSLContext" or "ssl.SSLSocket" across multiple threads.
-
gh-125996: Fix thread safety of "collections.OrderedDict". Patch by Kumar Aditya.
-
gh-133789: Fix unpickling of "pathlib" objects that were pickled in Python 3.13.
-
gh-127081: Fix libc thread safety issues with "dbm" by performing stateful operations in critical sections.
-
gh-132551: Make "io.BytesIO" safe in free-threaded build.
-
gh-131788: Make "ResourceTracker.send" from "multiprocessing" re- entrant safe
-
gh-118981: Fix potential hang in "multiprocessing.popen_spawn_posix" that can happen when the child proc dies early by closing the child fds right away.
-
gh-102431: Clarify constraints for "logical" arguments in methods of "decimal.Context".
-
gh-78319: UTF8 support for the IMAP APPEND command has been made RFC compliant.
-
bpo-38735: Fix failure when importing a module from the root directory on unix-like platforms with sys.pycache_prefix set.
-
bpo-41839: Allow negative priority values from "os.sched_get_priority_min()" and "os.sched_get_priority_max()" functions.
IDLE#
-
gh-96491: Deduplicate version number in IDLE shell title bar after saving to a file.
-
gh-139742: Colorize t-string prefixes for template strings in IDLE, as done for f-string prefixes.
Documentation#
-
gh-141994: "xml.sax.handler": Make Documentation of "xml.sax.handler.feature_external_ges" warn of opening up to external entity attacks. Patch by Sebastian Pipping.
-
gh-140578: Remove outdated sencence in the documentation for "multiprocessing", that implied that "concurrent.futures.ThreadPoolExecutor" did not exist.
Core and Builtins#
- gh-142048: Fix quadratically increasing garbage collection delays in free-threaded build.
Library#
- gh-116738: Fix thread safety issue with "re" scanner objects in free-threaded builds.
Core and Builtins#
-
gh-141930: When importing a module, use Python's regular file object to ensure that writes to ".pyc" files are complete or an appropriate error is raised.
-
gh-120158: Fix inconsistent state when enabling or disabling monitoring events too many times.
-
gh-139653: Only raise a "RecursionError" or trigger a fatal error if the stack pointer is both below the limit pointer and above the stack base. If outside of these bounds assume that it is OK. This prevents false positives when user-space threads swap stacks.
-
gh-139103: Improve multithreaded scaling of dataclasses on the free- threaded build.
-
gh-141579: Fix "sys.activate_stack_trampoline()" to properly support the "perf_jit" backend. Patch by Pablo Galindo.
-
gh-114203: Skip locking if object is already locked by two-mutex critical section.
-
gh-141528: Suggest using "concurrent.interpreters.Interpreter.close()" instead of the private "_interpreters.destroy" function when warning about remaining subinterpreters. Patch by Sergey Miryanov.
-
gh-141312: Fix the assertion failure in the "setstate" method of the range iterator when a non-integer argument is passed. Patch by Sergey Miryanov.
Library#
- gh-116738: Make csv module thread-safe on the free threaded build.
Core and Builtins#
- gh-140939: Fix memory leak when "bytearray" or "bytes" is formated with the "%*b" format with a large width that results in a "MemoryError".
Library#
- gh-140260: Fix "struct" data race in endian table initialization with subinterpreters. Patch by Shamil Abdulaev.
Core and Builtins#
-
gh-140530: Fix a reference leak when "raise exc from cause" fails. Patch by Bénédikt Tran.
-
gh-140373: Correctly emit "PY_UNWIND" event when generator object is closed. Patch by Mikhail Efimov.
-
gh-140576: Fixed crash in "tokenize.generate_tokens()" in case of specific incorrect input. Patch by Mikhail Efimov.
-
gh-140551: Fixed crash in "dict" if "dict.clear()" is called at the lookup stage. Patch by Mikhail Efimov and Inada Naoki.
-
gh-140517: Fixed a reference leak when iterating over the result of "map()" with "strict=True" when the input iterables have different lengths. Patch by Mikhail Efimov.
-
gh-140471: Fix potential buffer overflow in "ast.AST" node initialization when encountering malformed "_fields" containing non-"str".
-
gh-140431: Fix a crash in Python's garbage collector due to partially initialized coroutine objects when coroutine origin tracking depth is enabled ("sys.set_coroutine_origin_tracking_depth()").
Library#
- gh-140398: Fix memory leaks in "readline" functions "read_init_file()", "read_history_file()", "write_history_file()", and "append_history_file()" when "PySys_Audit()" fails.
Core and Builtins#
-
gh-140406: Fix memory leak when an object's "hash()" method returns an object that isn't an "int".
-
gh-140358: Restore elapsed time and unreachable object count in GC debug output. These were inadvertently removed during a refactor of "gc.c". The debug log now again reports elapsed collection time and the number of unreachable objects. Contributed by Pål Grønås Drange.
-
gh-140306: Fix memory leaks in cross-interpreter channel operations and shared namespace handling.
-
gh-140301: Fix memory leak of "PyConfig" in subinterpreters.
-
gh-140257: Fix data race between interpreter_clear() and take_gil() on eval_breaker during finalization with daemon threads.
-
gh-139951: Fixes a regression in GC performance for a growing heap composed mostly of small tuples.
-
Counts number of actually tracked objects, instead of trackable objects. This ensures that untracking tuples has the desired effect of reducing GC overhead.
-
Does not track most untrackable tuples during creation. This prevents large numbers of small tuples causing excessive GCs.
-
gh-140104: Fix a bug with exception handling in the JIT. Patch by Ken Jin. Bug reported by Daniel Diniz.
-
gh-140061: Fixing the checking of whether an object is uniquely referenced to ensure free-threaded compatibility. Patch by Sergey Miryanov.
-
gh-140067: Fix memory leak in sub-interpreter creation.
-
gh-140000: Fix potential memory leak when a reference cycle exists between an instance of "typing.TypeAliasType", "typing.TypeVar", "typing.ParamSpec", or "typing.TypeVarTuple" and its "name" attribute. Patch by Mikhail Efimov.
-
gh-139914: Restore support for HP PA-RISC, which has an upwards- growing stack.
-
gh-139988: Fix a memory leak when failing to create a "Union" type. Patch by Bénédikt Tran.
-
gh-139748: Fix reference leaks in error branches of functions accepting path strings or bytes such as "compile()" and "os.system()". Patch by Bénédikt Tran.
-
gh-139516: Fix lambda colon erroneously start format spec in f-string in tokenizer.
-
gh-139640: "ast.parse()" no longer emits syntax warnings for "return"/"break"/"continue" in "finally" (see PEP 765) -- they are only emitted during compilation.
-
gh-139640: Fix swallowing some syntax warnings in different modules if they accidentally have the same message and are emitted from the same line. Fix duplicated warnings in the "finally" block.
-
gh-63161: Support non-UTF-8 shebang and comments in Python source files if non-UTF-8 encoding is specified. Detect decoding error in comments for default (UTF-8) encoding. Show the line and position of decoding error for default encoding in a traceback. Show the line containing the coding cookie when it conflicts with the BOM in a traceback.
Library#
- gh-116738: Make "mmap" thread-safe on the free threaded build.
Core and Builtins#
-
gh-138558: Fix handling of unusual t-string annotations in annotationlib. Patch by Dave Peck.
-
gh-134466: Don't run PyREPL in a degraded environment where setting termios attributes is not allowed.
-
gh-138944: Fix "SyntaxError" message when invalid syntax appears on the same line as a valid "import ... as ..." or "from ... import ... as ..." statement. Patch by Brian Schubert.
-
gh-105487: Remove non-existent "copy()", "deepcopy()", and "bases" from the "dir()" entries of "types.GenericAlias".
-
gh-69605: Fix some standard library submodules missing from the REPL auto-completion of imports.
Library#
-
gh-116738: Make "cProfile" thread-safe on the free threaded build.
-
gh-138004: On Solaris/Illumos platforms, thread names are now encoded as ASCII to avoid errors on systems (e.g. OpenIndiana) that don't support non-ASCII names.
Core and Builtins#
-
gh-137433: Fix a potential deadlock in the free threading build when daemon threads enable or disable profiling or tracing while the main thread is shutting down the interpreter.
-
gh-137400: Fix a crash in the free threading build when disabling profiling or tracing across all threads with "PyEval_SetProfileAllThreads()" or "PyEval_SetTraceAllThreads()" or their Python equivalents "threading.settrace_all_threads()" and "threading.setprofile_all_threads()".
-
gh-58124: Fix name of the Python encoding in Unicode errors of the code page codec: use "cp65000" and "cp65001" instead of "CP_UTF7" and "CP_UTF8" which are not valid Python code names. Patch by Victor Stinner.
-
gh-132657: Improve performance of "frozenset" by removing locks in the free-threading build.
-
gh-133400: Fixed Ctrl+D (^D) behavior in _pyrepl module to match old pre-3.13 REPL behavior.
-
gh-128640: Fix a crash when using threads inside of a subinterpreter.
C API#
-
gh-137422: Fix free threading race condition in "PyImport_AddModuleRef()". It was previously possible for two calls to the function return two different objects, only one of which was stored in "sys.modules".
-
gh-140042: Removed the sqlite3_shutdown call that could cause closing connections for sqlite when used with multiple sub interpreters.
-
gh-141042: Make qNaN in "PyFloat_Pack2()" and "PyFloat_Pack4()", if while conversion to a narrower precision floating-point format --- the remaining after truncation payload will be zero. Patch by Sergey B Kirpichev.
-
gh-140487: Fix "Py_RETURN_NOTIMPLEMENTED" in limited C API 3.11 and older: don't treat "Py_NotImplemented" as immortal. Patch by Victor Stinner.
-
gh-140153: Fix "Py_REFCNT()" definition on limited C API 3.11-3.13. Patch by Victor Stinner.
-
gh-139653: Add "PyUnstable_ThreadState_SetStackProtection()" and "PyUnstable_ThreadState_ResetStackProtection()" functions to set the stack protection base address and stack protection size of a Python thread state. Patch by Victor Stinner.
Build#
-
gh-141808: Do not generate the jit stencils twice in case of PGO builds on Windows.
-
gh-141784: Fix "_remote_debugging_module.c" compilation on 32-bit Linux. Include Python.h before system headers to make sure that "_remote_debugging_module.c" uses the same types (ABI) than Python. Patch by Victor Stinner.
-
gh-140768: Warn when the WASI SDK version doesn't match what's supported.
-
gh-140513: Generate a clear compilation error when "_Py_TAIL_CALL_INTERP" is enabled but either "preserve_none" or "musttail" is not supported.
-
gh-140189: iOS builds were added to CI.
-
gh-138489: When cross-compiling for WASI by "build_wasm" or "build_emscripten", the "build-details.json" step is now included in the build process, just like with native builds.
This fixes the "libinstall" task which requires the "build- details.json" file during the process.
-
gh-137618: "PYTHON_FOR_REGEN" now requires Python 3.10 to Python 3.15. Patch by Adam Turner.
-
gh-123681: Check the "strftime()" behavior at runtime instead of at the compile time to support cross-compiling. Remove the internal macro "_Py_NORMALIZE_CENTURY".
Python 3.14.0 final#
Release date: 2025-10-07
macOS#
-
gh-124111: Update macOS installer to use Tcl/Tk 8.6.17.
-
gh-139573: Updated bundled version of OpenSSL to 3.0.18.
Windows#
- gh-139573: Updated bundled version of OpenSSL to 3.0.18.
Tools/Demos#
-
gh-139330: SBOM generation tool didn't cross-check the version and checksum values against the "Modules/expat/refresh.sh" script, leading to the values becoming out-of-date during routine updates.
-
gh-132006: XCframeworks now include privacy manifests to satisfy Apple App Store submission requirements.
-
gh-138171: A script for building an iOS XCframework was added. As part of this change, the top level "iOS" folder has been moved to be a subdirectory of the "Apple" folder.
Security#
- gh-139400: "xml.parsers.expat": Make sure that parent Expat parsers are only garbage-collected once they are no longer referenced by subparsers created by "ExternalEntityParserCreate()". Patch by Sebastian Pipping.
Library#
- gh-139312: Upgrade bundled libexpat to 2.7.3
Python 3.14.0 release candidate 3#
Release date: 2025-09-18
Windows#
- gh-138896: Fix error installing C runtime on non-updated Windows machines
Tools/Demos#
- gh-137873: The iOS test runner has been simplified, resolving some issues that have been observed using the runner in GitHub Actions and Azure Pipelines test environments.
Security#
- gh-135661: Fix CDATA section parsing in "html.parser.HTMLParser" according to the HTML5 standard: "] ]>" and "]] >" no longer end the CDATA section. Add private method "_set_support_cdata()" which can be used to specify how to parse "<[CDATA[" --- as a CDATA section in foreign content (SVG or MathML) or as a bogus comment in the HTML namespace.
Library#
-
gh-138998: Update bundled libexpat to 2.7.2
-
gh-118803: Add back "collections.abc.ByteString" and "typing.ByteString". Both had been removed in prior alpha, beta and release candidates for Python 3.14, but their removal has now been postponed to Python 3.17.
-
gh-137226: Fix "typing.get_type_hints()" calls on generic "typing.TypedDict" classes defined with string annotations.
-
gh-138804: Raise "TypeError" instead of "AttributeError" when an argument of incorrect type is passed to "shlex.quote()". This restores the behavior of the function prior to 3.14.
-
gh-128636: Fix crash in PyREPL when os.environ is overwritten with an invalid value for mac
-
gh-138514: Raise "ValueError" when a multi-character string is passed to the echo_char parameter of "getpass.getpass()". Patch by Benjamin Johnson.
-
gh-138515: "email" is added to Emscripten build.
-
gh-99948: "ctypes.util.find_library()" now works in Emscripten build.
-
gh-138253: Add the block parameter in the "put()" and "get()" methods of the "concurrent.interpreters" queues for compatibility with the "queue.Queue" interface.
-
gh-138133: Prevent infinite traceback loop when sending CTRL^C to Python through "strace".
-
gh-134869: Fix an issue where pressing Ctrl+C during tab completion in the REPL would leave the autocompletion menu in a corrupted state.
-
gh-90548: Fix "musl" detection for "platform.libc_ver()" on Alpine Linux if compiled with --strip-all.
-
gh-136134: "SMTP.auth_cram_md5()" now raises an "SMTPException" instead of a "ValueError" if Python has been built without MD5 support. In particular, "SMTP" clients will not attempt to use this method even if the remote server is assumed to support it. Patch by Bénédikt Tran.
-
gh-136134: "IMAP4.login_cram_md5" now raises an "IMAP4.error" if CRAM-MD5 authentication is not supported. Patch by Bénédikt Tran.
-
gh-134953: Expand "_colorize" theme with "keyword_constant" and implement in repl.
Core and Builtins#
-
gh-71810: Raise "OverflowError" for "(-1).to_bytes()" for signed conversions when bytes count is zero. Patch by Sergey B Kirpichev.
-
gh-138192: Fix "contextvars" initialization so that all subinterpreters are assigned the "MISSING" value.
-
gh-138479: Fix a crash when a generic object's "typing_subst" returns an object that isn't a "tuple".
-
gh-138372: Fix "SyntaxWarning" emitted for erroneous subscript expressions involving template string literals. Patch by Brian Schubert.
-
gh-138318: The default REPL now avoids highlighting built-in names (for instance "set" or "format()") when they are used as attribute names (for instance in "value.set" or "text.format").
-
gh-138349: Fix crash in certain cases where a module contains both a module-level annotation and a comprehension.
-
gh-137384: Fix a crash when using the "warnings" module in a finalizer at shutdown. Patch by Kumar Aditya.
-
gh-137883: Fix runaway recursion when calling a function with keyword arguments.
-
gh-137079: Fix keyword typo recognition when parsing files. Patch by Pablo Galindo.
-
gh-137728: Fix the JIT's handling of many local variables. This previously caused a segfault.
-
gh-137576: Fix for incorrect source code being shown in tracebacks from the Basic REPL when "PYTHONSTARTUP" is given. Patch by Adam Hartz.
Python 3.14.0 release candidate 2#
Release date: 2025-08-14
macOS#
-
gh-137450: macOS installer shell path management improvements: separate the installer "Shell profile updater" postinstall script from the "Update Shell Profile.command" to enable more robust error handling.
-
gh-137134: Update macOS installer to ship with SQLite version 3.50.4.
Windows#
- gh-137134: Update Windows installer to ship with SQLite 3.50.4.
Library#
-
gh-137426: Remove the code deprecation of "importlib.abc.ResourceLoader". It is documented as deprecated, but left for backwards compatibility with other classes in "importlib.abc".
-
gh-137282: Fix tab completion and "dir()" on "concurrent.futures".
-
gh-137257: Bump the version of pip bundled in ensurepip to version 25.2
-
gh-137226: Fix behavior of "annotationlib.ForwardRef.evaluate()" when the type_params parameter is passed and the name of a type param is also present in an enclosing scope.
-
gh-130522: Fix unraisable "TypeError" raised during interpreter shutdown in the "threading" module.
-
gh-137059: Fix handling of file URLs with a Windows drive letter in the URL authority by "urllib.request.url2pathname()". This fixes a regression in earlier pre-releases of Python 3.14.
-
gh-130577: "tarfile" now validates archives to ensure member offsets are non-negative. (Contributed by Alexander Enrique Urieles Nieto in gh-130577.)
-
gh-135228: When "dataclasses" replaces a class with a slotted dataclass, the original class can now be garbage collected again. Earlier changes in Python 3.14 caused this class to always remain in existence together with the replacement class synthesized by "dataclasses".
Documentation#
- gh-136155: We are now checking for fatal errors in EPUB builds in CI.
Core and Builtins#
-
gh-137400: Fix a crash in the free threading build when disabling profiling or tracing across all threads with "PyEval_SetProfileAllThreads()" or "PyEval_SetTraceAllThreads()" or their Python equivalents "threading.settrace_all_threads()" and "threading.setprofile_all_threads()".
-
gh-137314: Fixed a regression where raw f-strings incorrectly interpreted escape sequences in format specifications. Raw f-strings now properly preserve literal backslashes in format specs, matching the behavior from Python 3.11. For example, "rf"{obj:\xFF}"" now correctly produces "'\xFF'" instead of "'ÿ'". Patch by Pablo Galindo.
-
gh-137308: A standalone docstring in a node body is optimized as a "pass" statement to ensure that the node's body is never empty. There was a "ValueError" in "compile()" otherwise.
-
gh-137288: Fix bug where some bytecode instructions of a boolean expression are not associated with the correct exception handler.
-
gh-134291: Remove some newer macOS API usage from the JIT compiler in order to restore compatibility with older OSX 10.15 deployment targets.
-
gh-131338: Disable computed stack limit checks on non-glibc linux platforms to fix crashes on deep recursion.
-
gh-136870: Fix data races while de-instrumenting bytecode of code objects running concurrently in threads.
C API#
- gh-137573: Mark "_PyOptimizer_Optimize" as "Py_NO_INLINE" to prevent stack overflow crashes on macOS.
Build#
- gh-132339: Add support for OpenSSL 3.5.
Python 3.14.0 release candidate 1#
Release date: 2025-07-22
Tools/Demos#
- gh-136251: Fixes and usability improvements for "Tools/wasm/emscripten/web_example"
Security#
-
gh-135661: Fix parsing attributes with whitespaces around the "=" separator in "html.parser.HTMLParser" according to the HTML5 standard.
-
gh-118350: Fix support of escapable raw text mode (elements "textarea" and "title") in "html.parser.HTMLParser".
Library#
-
gh-136170: Removed the unreleased "zipfile.ZipFile.data_offset" property added in 3.14.0a7 as it wasn't fully clear which behavior it should have in some situations so the result was not always what a user might expect.
-
gh-124621: pyrepl now works in Emscripten.
-
gh-136874: Discard URL query and fragment in "urllib.request.url2pathname()".
-
gh-130645: Enable color help by default in "argparse".
-
gh-136549: Fix signature of "threading.excepthook()".
-
gh-136523: Fix "wave.Wave_write" emitting an unraisable when open raises.
-
gh-52876: Add missing "keepends" (default "True") parameter to "codecs.StreamReaderWriter.readline()" and "codecs.StreamReaderWriter.readlines()".
-
gh-136470: Correct "concurrent.futures.InterpreterPoolExecutor"'s default thread name.
-
gh-136476: Fix a bug that was causing the "get_async_stack_trace" function to miss some frames in the stack trace.
-
gh-136434: Fix docs generation of "UnboundItem" in "concurrent.interpreters" when running with "-OO".
-
gh-136380: Raises "AttributeError" when accessing "concurrent.futures.InterpreterPoolExecutor" and subinterpreters are not available.
-
gh-134759: Fix "UnboundLocalError" in "email.message.Message.get_payload()" when the payload to decode is a "bytes" object. Patch by Kliment Lamonov.
-
gh-134657: "asyncio": Remove some private names from "asyncio.all".
Core and Builtins#
- gh-136801: Fix PyREPL syntax highlighting on match cases after multi-line case. Contributed by Olga Matoula.
Library#
- gh-136421: Fix crash when initializing "datetime" concurrently.
Core and Builtins#
-
gh-136541: Fix some issues with the perf trampolines on x86-64 and aarch64. The trampolines were not being generated correctly for some cases, which could lead to the perf integration not working correctly. Patch by Pablo Galindo.
-
gh-136517: Fixed a typo that prevented printing of uncollectable objects when the "gc.DEBUG_UNCOLLECTABLE" mode was set.
-
gh-136525: Fix issue where per-thread bytecode was not instrumented for newly created threads.
-
gh-132661: "Interpolation.expression" now has a default, the empty string.
-
gh-132661: Reflect recent PEP 750 change.
Disallow concatenation of "string.templatelib.Template" and "str". Also, disallow implicit concatenation of t-string literals with string or f-string literals.
Library#
- gh-116738: Make functions in "grp" thread-safe on the free threaded build.
Core and Builtins#
-
gh-135148: Fixed a bug where f-string debug expressions (using =) would incorrectly strip out parts of strings containing escaped quotes and # characters. Patch by Pablo Galindo.
-
gh-133136: Limit excess memory usage in the free threading build when a large dictionary or list is resized and accessed by multiple threads.
-
gh-91153: Fix a crash when a "bytearray" is concurrently mutated during item assignment.
-
gh-127971: Fix off-by-one read beyond the end of a string in string search.
C API#
-
gh-112068: Revert support of nullable arguments in "PyArg_Parse()".
-
gh-133296: New variants for the critical section API that accept one or two "PyMutex" pointers rather than "PyObject" instances are now public in the non-limited C API.
-
gh-134009: Expose "PyMutex_IsLocked()" as part of the public C API.
Build#
- gh-135621: PyREPL no longer depends on the "curses" standard library. Contributed by Łukasz Langa.
Python 3.14.0 beta 4#
Release date: 2025-07-08
Tools/Demos#
-
gh-135968: Stubs for "strip" are now provided as part of an iOS install.
-
gh-133600: Backport file reorganization for Tools/wasm/wasi.
This should make backporting future code changes easier. It also simplifies instructions around how to do WASI builds in the devguide.
Tests#
-
gh-135966: The iOS testbed now handles the "app_packages" folder as a site directory.
-
gh-135494: Fix regrtest to support excluding tests from "--pgo" tests. Patch by Victor Stinner.
Security#
-
gh-136053: "marshal": fix a possible crash when deserializing "slice" objects.
-
gh-135661: Fix parsing start and end tags in "html.parser.HTMLParser" according to the HTML5 standard.
-
Whitespaces no longer accepted between "</" and the tag name. E.g. "</ script>" does not end the script section.
-
Vertical tabulation ("\v") and non-ASCII whitespaces no longer recognized as whitespaces. The only whitespaces are "\t\n\r\f" and space.
-
Null character (U+0000) no longer ends the tag name.
-
Attributes and slashes after the tag name in end tags are now ignored, instead of terminating after the first ">" in quoted attribute value. E.g. "".
-
Multiple slashes and whitespaces between the last attribute and closing ">" are now ignored in both start and end tags. E.g. "".
-
Multiple "=" between attribute name and value are no longer collapsed. E.g. "" produces attribute "foo" with value "=bar".
-
[Reverted in gh-136927] Whitespaces between the "=" separator and attribute name or value are no longer ignored. E.g. "" produces two attributes "foo" and "=bar", both with value None; "" produces two attributes: "foo" with value "" and "bar" with value None.
-
gh-102555: Fix comment parsing in "html.parser.HTMLParser" according to the HTML5 standard. "--!>" now ends the comment. "-- >" no longer ends the comment. Support abnormally ended empty comments "<-->" and "<--->".
Library#
-
gh-136286: Fix pickling failures for protocols 0 and 1 for many objects realted to subinterpreters.
-
gh-136316: Improve support for evaluating nested forward references in "typing.evaluate_forward_ref()".
-
gh-85702: If "zoneinfo._common.load_tzdata" is given a package without a resource a "zoneinfo.ZoneInfoNotFoundError" is raised rather than a "PermissionError". Patch by Victor Stinner.
-
gh-136028: Fix parsing month names containing "İ" (U+0130, LATIN CAPITAL LETTER I WITH DOT ABOVE) in "time.strptime()". This affects locales az_AZ, ber_DZ, ber_MA and crh_UA.
-
gh-135995: In the palmos encoding, make byte "0x9b" decode to "›" (U+203A - SINGLE RIGHT-POINTING ANGLE QUOTATION MARK).
-
gh-53203: Fix "time.strptime()" for "%c" and "%x" formats on locales byn_ER, wal_ET and lzh_TW, and for "%X" format on locales ar_SA, bg_BG and lzh_TW.
-
gh-91555: An earlier change, which was introduced in 3.14.0b2, has been reverted. It disabled logging for a logger during handling of log messages for that logger. Since the reversion, the behaviour should be as it was before 3.14.0b2.
-
gh-135878: Fixes a crash of "types.SimpleNamespace" on free threading builds, when several threads were calling its "repr()" method at the same time.
-
gh-135836: Fix "IndexError" in "asyncio.loop.create_connection()" that could occur when non-"OSError" exception is raised during connection and socket's "close()" raises "OSError".
-
gh-135836: Fix "IndexError" in "asyncio.loop.create_connection()" that could occur when the Happy Eyeballs algorithm resulted in an empty exceptions list during connection attempts.
-
gh-135855: Raise "TypeError" instead of "SystemError" when "_interpreters.setmainattrs()" is passed a non-dict object. Patch by Brian Schubert.
-
gh-135815: "netrc": skip security checks if "os.getuid()" is missing. Patch by Bénédikt Tran.
-
gh-135640: Address bug where it was possible to call "xml.etree.ElementTree.ElementTree.write()" on an ElementTree object with an invalid root element. This behavior blanked the file passed to "write" if it already existed.
-
gh-135645: Added "supports_isolated_interpreters" field to "sys.implementation".
-
gh-135646: Raise consistent "NameError" exceptions in "annotationlib.ForwardRef.evaluate()"
-
gh-135557: Fix races on "heapq" updates and "list" reads on the free threaded build.
-
gh-119180: Only fetch globals and locals if necessary in "annotationlib.get_annotations()"
-
gh-135561: Fix a crash on DEBUG builds when an HACL* HMAC routine fails. Patch by Bénédikt Tran.
-
gh-135487: Fix "reprlib.Repr.repr_int()" when given integers with more than "sys.get_int_max_str_digits()" digits. Patch by Bénédikt Tran.
-
gh-135335: "multiprocessing": Flush "stdout" and "stderr" after preloading modules in the "forkserver".
-
gh-135069: Fix the "Invalid error handling" exception in "encodings.idna.IncrementalDecoder" to correctly replace the 'errors' parameter.
-
gh-130662: +Accept leading zeros in precision and width fields for +:class:"Decimal" formatting, for example "format(Decimal(1.25), '.016f')".
-
gh-130662: Accept leading zeros in precision and width fields for "Fraction" formatting, for example "format(Fraction(1, 3), '.016f')".
-
gh-87790: Support underscore and comma as thousands separators in the fractional part for "Fraction"'s formatting. Patch by Sergey B Kirpichev.
-
gh-87790: Support underscore and comma as thousands separators in the fractional part for "Decimal"'s formatting. Patch by Sergey B Kirpichev.
-
gh-130664: Handle corner-case for "Fraction"'s formatting: treat zero-padding (preceding the width field by a zero ("'0'") character) as an equivalent to a fill character of "'0'" with an alignment type of "'='", just as in case of "float"'s.
Documentation#
- gh-136155: EPUB builds are fixed by excluding non-XHTML-compatible tags.
Core and Builtins#
-
gh-109700: Fix memory error handling in "PyDict_SetDefault()".
-
gh-78465: Fix error message for "cls.new(cls, ...)" where "cls" is not instantiable builtin or extension type (with "tp_new" set to "NULL").
-
gh-129958: Differentiate between t-strings and f-strings in syntax error for newlines in format specifiers of single-quoted interpolated strings.
-
gh-135871: Non-blocking mutex lock attempts now return immediately when the lock is busy instead of briefly spinning in the free threading build.
-
gh-135106: Restrict the trashcan mechanism to GC'ed objects and untrack them while in the trashcan to prevent the GC and trashcan mechanisms conflicting.
-
gh-135607: Fix potential "weakref" races in an object's destructor on the free threaded build.
-
gh-135608: Fix a crash in the JIT involving attributes of modules.
-
gh-135543: Emit "sys.remote_exec" audit event when "sys.remote_exec()" is called and migrate "remote_debugger_script" to "cpython.remote_debugger_script".
-
gh-134280: Disable constant folding for "~" with a boolean argument. This moves the deprecation warning from compile time to runtime.
C API#
- gh-135906: Fix compilation errors when compiling the internal headers with a C++ compiler.
Build#
- gh-134273: Add support for configuring compiler flags for the JIT with "CFLAGS_JIT"
Python 3.14.0 beta 3#
Release date: 2025-06-17
Windows#
- gh-135099: Fix a crash that could occur on Windows when a background thread waits on a "PyMutex" while the main thread is shutting down the interpreter.
Tests#
-
gh-132815: Fix test__opcode: add "JUMP_BACKWARD" to specialization stats.
-
gh-135489: Show verbose output for failing tests during PGO profiling step with --enable-optimizations.
-
gh-135120: Add "test.support.subTests()".
Security#
-
gh-135462: Fix quadratic complexity in processing specially crafted input in "html.parser.HTMLParser". End-of-file errors are now handled according to the HTML5 specs -- comments and declarations are automatically closed, tags are ignored.
-
gh-135034: Fixes multiple issues that allowed "tarfile" extraction filters ("filter="data"" and "filter="tar"") to be bypassed using crafted symlinks and hard links.
Addresses CVE 2024-12718, CVE 2025-4138, CVE 2025-4330, and CVE 2025-4517.
Library#
-
gh-65697: "configparser"'s error message when attempting to write an invalid key is now more helpful.
-
gh-135497: Fix "os.getlogin()" failing for longer usernames on BSD- based platforms.
-
gh-135429: Fix the argument mismatch in "_lsprof" for "PY_THROW" event.
-
gh-135368: Fix "unittest.mock.Mock" generation on "dataclasses.dataclass()" objects. Now all special attributes are set as it was before gh-124429.
-
gh-133967: Do not normalize "locale" name 'C.UTF-8' to 'en_US.UTF-8'.
-
gh-135321: Raise a correct exception for values greater than 0x7fffffff for the "BINSTRING" opcode in the C implementation of "pickle".
-
gh-135276: Backported bugfixes in zipfile.Path from zipp 3.23. Fixed ".name", ".stem" and other basename-based properties on Windows when working with a zipfile on disk.
-
gh-135244: "uuid": when the MAC address cannot be determined, the 48-bit node ID is now generated with a cryptographically-secure pseudo-random number generator (CSPRNG) as per RFC 9562, §6.10.3. This affects "uuid1()" and "uuid6()".
-
gh-134970: Fix the "unknown action" exception in "argparse.ArgumentParser.add_argument_group()" to correctly replace the action class.
-
gh-134718: "ast.dump()" now only omits "None" and "[]" values if they are default values.
-
gh-134939: Add the "concurrent.interpreters" module. See PEP 734.
-
gh-134885: Fix possible crash in the "compression.zstd" module related to setting parameter types. Patch by Jelle Zijlstra.
-
gh-134857: Improve error report for "doctest"s run with "unittest". Remove "doctest" module frames from tracebacks and redundant newline character from a failure message.
-
gh-128840: Fix parsing long IPv6 addresses with embedded IPv4 address.
-
gh-134637: Fix performance regression in calling a "ctypes" function pointer in free threading.
-
gh-134696: Built-in HACL and OpenSSL implementations of hash function constructors now correctly accept the same documented* named arguments. For instance, "md5()" could be previously invoked as "md5(data=data)" or "md5(string=string)" depending on the underlying implementation but these calls were not compatible. Patch by Bénédikt Tran.
-
gh-134151: "email": Fix "TypeError" in "email.utils.decode_params()" when sorting RFC 2231 continuations that contain an unnumbered section.
-
gh-134210: "curses.window.getch()" now correctly handles signals. Patch by Bénédikt Tran.
-
gh-134152: "email": Fix parsing of email message ID with invalid domain.
-
gh-133489: "random.getrandbits()" can now generate more that 2^31 bits. "random.randbytes()" can now generate more that 256 MiB.
-
gh-132813: Improve error messages for incorrect types and values of "csv.Dialect" attributes.
-
gh-132969: Prevent the "ProcessPoolExecutor" executor thread, which remains running when "shutdown(wait=False)", from attempting to adjust the pool's worker processes after the object state has already been reset during shutdown. A combination of conditions, including a worker process having terminated abormally, resulted in an exception and a potential hang when the still-running executor thread attempted to replace dead workers within the pool.
-
gh-127081: Fix libc thread safety issues with "os" by replacing "getlogin" with "getlogin_r" re-entrant version.
-
gh-131884: Fix formatting issues in "json.dump()" when both indent and skipkeys are used.
-
gh-130999: Avoid exiting the new REPL and offer suggestions even if there are non-string candidates when errors occur.
Documentation#
-
gh-135171: Document that the iterator for the leftmost "for" clause in the generator expression is created immediately.
-
bpo-45210: Document that error indicator may be set in tp_dealloc, and how to avoid clobbering it.
Core and Builtins#
-
gh-135496: Fix typo in the f-string conversion type error ("exclamanation" -> "exclamation").
-
gh-135371: Fixed "asyncio" debugging tools to properly display internal coroutine call stacks alongside external task dependencies. The "python -m asyncio ps" and "python -m asyncio pstree" commands now show complete execution context. Patch by Pablo Galindo.
Library#
- gh-127319: Set the "allow_reuse_port" class variable to "False" on the XMLRPC, logging, and HTTP servers. This matches the behavior in prior Python releases, which is to not allow port reuse.
Core and Builtins#
-
gh-135171: Reverts the behavior of async generator expressions when created with object w/o aiter method to the pre-3.13 behavior of raising a TypeError.
-
gh-130077: Properly raise custom syntax errors when incorrect syntax containing names that are prefixes of soft keywords is encountered. Patch by Pablo Galindo.
-
gh-135171: Reverts the behavior of generator expressions when created with a non-iterable to the pre-3.13 behavior of raising a TypeError. It is no longer possible to cause a crash in the debugger by altering the generator expression's local variables. This is achieved by moving the "GET_ITER" instruction back to the creation of the generator expression and adding an additional check to "FOR_ITER".
Library#
- gh-116738: Make methods in "heapq" thread-safe on the free threaded build.
Core and Builtins#
-
gh-134876: Add support to PEP 768 remote debugging for Linux kernels which don't have CONFIG_CROSS_MEMORY_ATTACH configured.
-
gh-134889: Fix handling of a few opcodes that leave operands on the stack when optimizing "LOAD_FAST".
Library#
- gh-134908: Fix crash when iterating over lines in a text file on the free threaded build.
Core and Builtins#
-
gh-132617: Fix "dict.update()" modification check that could incorrectly raise a "dict mutated during update" error when a different dictionary was modified that happens to share the same underlying keys object.
-
gh-134679: Fix crash in the free threading build's QSBR code that could occur when changing an object's "dict" attribute.
-
gh-127682: No longer call "iter" twice in list comprehensions. This brings the behavior of list comprehensions in line with other forms of iteration
-
gh-133912: Fix the C API function "PyObject_GenericSetDict" to handle extension classes with inline values.
C API#
-
gh-134989: Fix "Py_RETURN_NONE", "Py_RETURN_TRUE" and "Py_RETURN_FALSE" macros in the limited C API 3.11 and older: don't treat "Py_None", "Py_True" and "Py_False" as immortal. Patch by Victor Stinner.
-
gh-134989: Implement "PyObject_DelAttr()" and "PyObject_DelAttrString()" as macros in the limited C API 3.12 and older. Patch by Victor Stinner.
-
gh-133968: Add "PyUnicodeWriter_WriteASCII()" function to write an ASCII string into a "PyUnicodeWriter". The function is faster than "PyUnicodeWriter_WriteUTF8()", but has an undefined behavior if the input string contains non-ASCII characters. Patch by Victor Stinner.
Build#
-
gh-119132: Remove "experimental" tag from the CPython free-threading build.
-
gh-135497: Fix the detection of "MAXLOGNAME" in the "configure.ac" script.
-
gh-134923: Windows builds with profile-guided optimization enabled now use "/GENPROFILE" and "/USEPROFILE" instead of deprecated "/LTCG:" options.
-
gh-134774: Fix "Py_DEBUG" macro redefinition warnings on Windows debug builds. Patch by Chris Eibl.
-
gh-134632: Fixed "build-details.json" generation to use "INCLUDEPY", in order to reference the "pythonX.Y" subdirectory of the include directory, as required in PEP 739, instead of the top-level include directory.
Python 3.14.0 beta 2#
Release date: 2025-05-26
Windows#
-
gh-130727: Fix a race in internal calls into WMI that can result in an "invalid handle" exception under high load. Patch by Chris Eibl.
-
gh-76023: Make "os.path.realpath()" ignore Windows error 1005 when in non-strict mode.
-
gh-133779: Reverts the change to generate different "pyconfig.h" files based on compiler settings, as it was frequently causing extension builds to break. In particular, the "Py_GIL_DISABLED" preprocessor variable must now always be defined explicitly when compiling for the experimental free-threaded runtime. The "sysconfig.get_config_var()" function can be used to determine whether the current runtime was compiled with that flag or not.
-
gh-133626: Ensures packages are not accidentally bundled into the traditional installer.
Tools/Demos#
- gh-134215: REPL import autocomplete only suggests private modules when explicitly specified.
Tests#
-
gh-133744: Fix multiprocessing interrupt test. Add an event to synchronize the parent process with the child process: wait until the child process starts sleeping. Patch by Victor Stinner.
-
gh-133682: Fixed test case "test.test_annotationlib.TestStringFormat.test_displays" which ensures proper handling of complex data structures (lists, sets, dictionaries, and tuples) in string annotations.
-
gh-133639: Fix "TestPyReplAutoindent.test_auto_indent_default()" doesn't run "input_code".
Security#
-
gh-133767: Fix use-after-free in the "unicode-escape" decoder with a non-"strict" error handler.
-
gh-128840: Short-circuit the processing of long IPv6 addresses early in "ipaddress" to prevent excessive memory consumption and a minor denial-of-service.
Library#
-
gh-132710: If possible, ensure that "uuid.getnode()" returns the same result even across different processes. Previously, the result was constant only within the same process. Patch by Bénédikt Tran.
-
gh-80334: "multiprocessing.freeze_support()" now checks for work on any "spawn" start method platform rather than only on Windows.
-
gh-134582: Fix tokenize.untokenize() round-trip errors related to t-strings braces escaping
-
gh-134546: Ensure "pdb" remote debugging script is readable by remote Python process.
-
gh-134451: Converted "asyncio.tools.CycleFoundException" from dataclass to a regular exception type.
-
gh-114177: Fix "asyncio" to not close subprocess pipes which would otherwise error out when the event loop is already closed.
-
gh-90871: Fixed an off by one error concerning the backlog parameter in "create_unix_server()". Contributed by Christian Harries.
-
gh-134323: Fix the "threading.RLock.locked()" method.
-
gh-86802: Fixed asyncio memory leak in cancelled shield tasks. For shielded tasks where the shield was cancelled, log potential exceptions through the exception handler. Contributed by Christian Harries.
-
gh-134209: "curses": The "curses.window.instr()" and "curses.window.getstr()" methods now allocate their internal buffer on the heap instead of the stack; in addition, the max buffer size is increased from 1023 to 2047.
-
gh-134235: Updated tab completion on REPL to include builtin modules. Contributed by Tom Wang, Hunter Young
-
gh-134152: Fixed "UnboundLocalError" that could occur during "email" header parsing if an expected trailing delimiter is missing in some contexts.
-
gh-134168: "http.server": Fix IPv6 address binding and "--directory" handling when using HTTPS.
-
gh-62184: Remove import of C implementation of "io.FileIO" from Python implementation which has its own implementation
-
gh-133982: Emit "RuntimeWarning" in the Python implementation of "io" when the file-like object is not closed explicitly in the presence of multiple I/O layers.
-
gh-133890: The "tarfile" module now handles "UnicodeEncodeError" in the same way as "OSError" when cannot extract a member.
-
gh-134097: Fix interaction of the new REPL and "-X showrefcount" command line option.
-
gh-133889: The generated directory listing page in "http.server.SimpleHTTPRequestHandler" now only shows the decoded path component of the requested URL, and not the query and fragment.
-
gh-134098: Fix handling paths that end with a percent-encoded slash ("%2f" or "%2F") in "http.server.SimpleHTTPRequestHandler".
-
gh-132124: On POSIX-compliant systems, "multiprocessing.util.get_temp_dir()" now ignores "TMPDIR" (and similar environment variables) if the path length of "AF_UNIX" socket files exceeds the platform-specific maximum length when using the forkserver start method. Patch by Bénédikt Tran.
-
gh-134062: "ipaddress": fix collisions in "hash()" for "IPv4Network" and "IPv6Network" objects.
-
gh-133970: Make "string.templatelib.Template" and "string.templatelib.Interpolation" generic.
-
gh-71253: Raise "ValueError" in "open()" if opener returns a negative file-descriptor in the Python implementation of "io" to match the C implementation.
-
gh-133960: Simplify and improve "typing.evaluate_forward_ref()". It now no longer raises errors on certain invalid types. In several situations, it is now able to evaluate forward references that were previously unsupported.
-
gh-133925: Make the private class "typing._UnionGenericAlias" hashable.
-
gh-133653: Fix "argparse.ArgumentParser" with the formatter_class argument. Fix TypeError when formatter_class is a custom subclass of "HelpFormatter". Fix TypeError when formatter_class is not a subclass of "HelpFormatter" and non-standard prefix_char is used. Fix support of colorizing when formatter_class is not a subclass of "HelpFormatter".
-
gh-132641: Fixed a race in "functools.lru_cache()" under free- threading.
-
gh-133783: Fix bug with applying "copy.replace()" to "ast" objects. Attributes that default to "None" were incorrectly treated as required for manually created AST nodes.
-
gh-133684: Fix bug where "annotationlib.get_annotations()" would return the wrong result for certain classes that are part of a class hierarchy where "from future import annotations" is used.
-
gh-77057: Fix handling of invalid markup declarations in "html.parser.HTMLParser".
-
gh-130328: Speedup pasting in "PyREPL" on Windows in a legacy console. Patch by Chris Eibl.
-
gh-133701: Fix bug where "typing.TypedDict" classes defined under "from future import annotations" and inheriting from another "TypedDict" had an incorrect "annotations" attribute.
-
gh-133581: Improve unparsing of t-strings in "ast.unparse()" and "from future import annotations". Empty t-strings now round-trip correctly and formatting in interpolations is preserved. Patch by Jelle Zijlstra.
-
gh-133551: Support t-strings (PEP 750) in "annotationlib". Patch by Jelle Zijlstra.
-
gh-133439: Fix dot commands with trailing spaces are mistaken for multi-line SQL statements in the sqlite3 command-line interface.
-
gh-132493: Avoid accessing "annotations" unnecessarily in "inspect.signature()".
-
gh-132876: "ldexp()" on Windows doesn't round subnormal results before Windows 11, but should. Python's "math.ldexp()" wrapper now does round them, so results may change slightly, in rare cases of very small results, on Windows versions before 11.
-
gh-133009: "xml.etree.ElementTree": Fix a crash in "Element.deepcopy" when the element is concurrently mutated. Patch by Bénédikt Tran.
-
gh-91555: Ignore log messages generated during handling of log messages, to avoid deadlock or infinite recursion. [NOTE: This change has since been reverted.]
-
gh-125028: "functools.Placeholder" cannot be passed to "functools.partial()" as a keyword argument.
-
gh-62824: Fix aliases for "iso8859_8" encoding. Patch by Dave Goncalves.
-
gh-86155: "html.parser.HTMLParser.close()" no longer loses data when the "