|
| 1 | +.. date: 2026-09-29-16-32-46 |
| 2 | +.. gh-issue: 158446 |
| 3 | +.. nonce: dToaPr |
| 4 | +.. release date: 2026-10-01 |
| 5 | +.. section: Security |
| 6 | +
|
| 7 | +Fix a crash or incorrect output that could occur when formatting a |
| 8 | +:class:`float` or :class:`complex` with a precision close to the platform's |
| 9 | +``INT_MAX``. :c:func:`PyOS_double_to_string` now raises :exc:`ValueError` |
| 10 | +for any precision of that magnitude, regardless of presentation type or |
| 11 | +value, as the format string parsers already did for precisions above |
| 12 | +``INT_MAX``. |
| 13 | + |
| 14 | +.. |
| 15 | +
|
| 16 | +.. date: 2026-09-23-11-34-30 |
| 17 | +.. gh-issue: 156793 |
| 18 | +.. nonce: zC_AjF |
| 19 | +.. section: Security |
| 20 | +
|
| 21 | +:mod:`asyncio`: :meth:`loop.start_tls() <asyncio.loop.start_tls>` and |
| 22 | +:meth:`loop.create_connection() <asyncio.loop.create_connection>` now |
| 23 | +validate the *server_hostname* argument if an :class:`ssl.SSLContext` is |
| 24 | +passed with *check_hostname* set to ``True``, emitting |
| 25 | +:exc:`DeprecationWarning` if *server_hostname* is missing. (This will raise |
| 26 | +:exc:`ValueError` in Python 3.13 and later.) |
| 27 | + |
| 28 | +.. |
| 29 | +
|
| 30 | +.. date: 2026-09-16-14-05-19 |
| 31 | +.. gh-issue: 156793 |
| 32 | +.. nonce: Qa1T5Z |
| 33 | +.. section: Security |
| 34 | +
|
| 35 | +:meth:`ssl.SSLContext.wrap_bio` now validates its *server_side*, |
| 36 | +*server_hostname* and *session* arguments similar to |
| 37 | +:meth:`ssl.SSLContext.wrap_socket`, but for backward compatiblity reasons |
| 38 | +emits :exc:`DeprecationWarning` instead of :exc:`ValueError`. |
| 39 | + |
| 40 | +In particular, a context with :attr:`~ssl.SSLContext.check_hostname` enabled |
| 41 | +and no *server_hostname* passed to :meth:`!wrap_bio` now emits |
| 42 | +:exc:`DeprecationWarning` to indicate the hostname wasn't checked. (In |
| 43 | +Python 3.13 and later, this raises :exc:`ValueError`.) |
| 44 | + |
| 45 | +.. |
| 46 | +
|
| 47 | +.. date: 2026-09-10-13-38-11 |
| 48 | +.. gh-issue: 157265 |
| 49 | +.. nonce: -vYuMp |
| 50 | +.. section: Security |
| 51 | +
|
| 52 | +In :mod:`tarfile`, when extracting a link falls back to extracting a member |
| 53 | +of the archive, skip the member when the filter function returns None when |
| 54 | +called with the extracted member's name replaced with the link's. |
| 55 | + |
| 56 | +.. |
| 57 | +
|
| 58 | +.. date: 2026-09-06-11-02-46 |
| 59 | +.. gh-issue: 157190 |
| 60 | +.. nonce: tarhln |
| 61 | +.. section: Security |
| 62 | +
|
| 63 | +Fixed a vulnerability in the :mod:`tarfile` ``data`` and ``tar`` extraction |
| 64 | +filters where a crafted archive using a hard link to a symbolic link could |
| 65 | +change the permissions and modification time of a file outside the |
| 66 | +destination directory, and expose its contents inside the extracted tree. |
| 67 | +This addresses CVE 2026-82049. |
| 68 | + |
| 69 | +.. |
| 70 | +
|
| 71 | +.. date: 2026-08-31-16-47-33 |
| 72 | +.. gh-issue: 157953 |
| 73 | +.. nonce: KxCF5N |
| 74 | +.. section: Security |
| 75 | +
|
| 76 | +Update bundled `libexpat <https://libexpat.github.io/>`_ to version 2.8.5. |
| 77 | + |
| 78 | +.. |
| 79 | +
|
| 80 | +.. date: 2026-08-18-13-54-05 |
| 81 | +.. gh-issue: 156002 |
| 82 | +.. nonce: CcWXPP |
| 83 | +.. section: Security |
| 84 | +
|
| 85 | +Bound the amount of data :mod:`zipfile` decompresses per read for members |
| 86 | +compressed with bzip2, LZMA, or Zstandard, matching the existing limit for |
| 87 | +deflate. A small archive member could previously expand into an unbounded |
| 88 | +allocation even when read in small chunks. |
| 89 | + |
| 90 | +.. |
| 91 | +
|
| 92 | +.. date: 2026-08-13-13-08-11 |
| 93 | +.. gh-issue: 155999 |
| 94 | +.. nonce: Xt4rWq |
| 95 | +.. section: Security |
| 96 | +
|
| 97 | +Fix the :mod:`tarfile` ``tar`` and ``data`` extraction filters creating |
| 98 | +directories outside the destination for members whose name leaves the |
| 99 | +destination and returns to it, such as ``../evil/../dest/sub/file``. The |
| 100 | +containment check used the resolved path, but intermediate directories were |
| 101 | +created from the name as given. |
| 102 | + |
| 103 | +.. |
| 104 | +
|
| 105 | +.. date: 2026-08-10-12-00-00 |
| 106 | +.. gh-issue: 156293 |
| 107 | +.. nonce: sNIcbk |
| 108 | +.. section: Security |
| 109 | +
|
| 110 | +Fix a crash in :mod:`ssl` when an :attr:`~ssl.SSLContext.sni_callback` |
| 111 | +switches a connection to another :class:`~ssl.SSLContext` and the context |
| 112 | +that carries the callback is no longer referenced by the application. |
| 113 | +Servers that keep their ``sni_callback`` context alive (the usual case when |
| 114 | +it wraps the listening socket or is stored on the server object) were not |
| 115 | +affected. This addresses `CVE-2026-19445 |
| 116 | +<https://www.cve.org/CVERecord?id=CVE-2026-19445>`_. |
| 117 | + |
| 118 | +.. |
| 119 | +
|
| 120 | +.. date: 2026-08-06-11-43-20 |
| 121 | +.. gh-issue: 155292 |
| 122 | +.. nonce: j4pHBO |
| 123 | +.. section: Security |
| 124 | +
|
| 125 | +Change the :mod:`stringprep` module and :mod:`encodings.idna` codec to not |
| 126 | +consider Unicode codepoint attributes beyond those defined in :rfc:`3454`. |
| 127 | + |
| 128 | +.. |
| 129 | +
|
| 130 | +.. date: 2026-07-31-16-20-17 |
| 131 | +.. gh-issue: 155694 |
| 132 | +.. nonce: SsxlKG |
| 133 | +.. section: Security |
| 134 | +
|
| 135 | +Fix `CVE-2026-15806 <https://www.cve.org/CVERecord?id=CVE-2026-15806>`_ by |
| 136 | +scoping :class:`~urllib.request.HTTPPasswordMgr` credentials to the URL |
| 137 | +scheme, preventing credentials stored for an HTTPS URL from being used for a |
| 138 | +matching HTTP URL, while URIs without a scheme continue to match any scheme. |
| 139 | + |
| 140 | +.. |
| 141 | +
|
| 142 | +.. date: 2026-09-08-13-06-29 |
| 143 | +.. gh-issue: 156002 |
| 144 | +.. nonce: vmOC8T |
| 145 | +.. section: Library |
| 146 | +
|
| 147 | +:mod:`zipfile` again reads members through a third-party decompressor |
| 148 | +installed by monkey-patching the private ``_get_decompressor()`` to return |
| 149 | +an object that only implements old BZ2Decompressor API from Python 3.3. Note |
| 150 | +that decompressors without ``needs_input`` and two-argument ``decompress()`` |
| 151 | +are vulnerable to CVE 2026-15310. |
| 152 | + |
| 153 | +.. |
| 154 | +
|
| 155 | +.. date: 2026-08-26-02-30-00 |
| 156 | +.. gh-issue: 156353 |
| 157 | +.. nonce: abcdef |
| 158 | +.. section: Library |
| 159 | +
|
| 160 | +Fix :mod:`configparser` parsing when using whitespace in *delimiters*. |
| 161 | + |
| 162 | +.. |
| 163 | +
|
| 164 | +.. date: 2026-08-13-12-57-27 |
| 165 | +.. gh-issue: 155757 |
| 166 | +.. nonce: _5cg0h |
| 167 | +.. section: Build |
| 168 | +
|
| 169 | +Set the ``--argv0`` argument to wasmtime for WASI builds so the test suite |
| 170 | +passes. Otherwise the calculated paths to the stdlib for frozen modules is |
| 171 | +incorrect. |
0 commit comments