Python 3.10 reached end of life on 1 October 2026, and CPython no longer accepts fixes for it. Your code keeps running, but any new vulnerability in the interpreter or standard library stays unpatched upstream. The practical move is to pick a supported version (we'd pick 3.12 or later) and check which cloud runtime deadline hits your services first, because Google Cloud's date has already passed (4 October), Lambda's lands on 31 October, and Azure lists October 2026.
What happened: Python 3.10 reached end of life on 1 October 2026
Pablo Galindo announced the final build on October 1, 2026. The announcement post is blunt: "Python 3.10.22 is the final release of Python 3.10. After five years, the series has reached end of life and will receive no further security updates." It adds, "If you are still using Python 3.10, please plan your upgrade to a supported version."
The project's own planning document is stricter about what "frozen" means. PEP 619 says, "As of 2026-10-01, 3.10 has reached the end-of-life phase of its release cycle. 3.10.22 was the final security release. The codebase for 3.10 is now frozen and no further updates will be provided nor issues of any kind will be accepted on the bug tracker." So there's no point filing a bug against 3.10 either.
The date follows the usual cycle. The Python developer guide describes five release phases, with about two years of bugfix releases (18 months for versions before 3.13), then security-only fixes, ending five years after the first release. 3.10.0 shipped on 2021-10-04, so the 2026-10-01 cutoff is the schedule working as designed.
One date to keep separate: 31 October 2026 is when AWS Lambda deprecates its python3.10 runtime. It isn't the Python end-of-life date, which is 1 October.
What the last release fixed
The 3.10.22 release page lists eight CVEs. They touch ssl, tarfile, zipfile, stringprep and IDNA handling, and credential scoping in urllib.request, plus three fixes without CVE numbers (gh-158446, gh-157953 and gh-149018). The page itself states that 3.10.22 "reached end-of-life on 2026-10-01. It is no longer supported and does not receive security updates."
Those are the last fixes 3.10 will ever get. A future bug in those modules won't be patched on 3.10, and services that handle archives, TLS or outbound URLs use them directly.
Which Python version to move to
The devguide's table gives the runways. Each row is a supported version as of today.
| Version | Status | First release | End of life |
|---|---|---|---|
| 3.11 | Security fixes only | 2022-10-24 | 2027-10 |
| 3.12 | Security fixes only | 2023-10-02 | 2028-10 |
| 3.13 | Security fixes only | 2024-10-07 | 2029-10 |
| 3.14 | Bugfix | 2025-10-07 | 2030-10 |
The announcement confirms the 3.11 date: "Python 3.11 remains in security-fix-only mode until October 2027, as described in PEP 664." It also says 3.13.16 is the final full maintenance release, so later 3.13 releases carry security fixes only.
3.14 has the longest runway, to October 2030. 3.12 gives you about two years of upstream support, and 3.13 about three. 3.11 gives you twelve months.
Cloud runtime dates
Upstream is only one clock. If you run on a managed runtime, the vendor's date may come first.
| Runtime | Python 3.10 | Python 3.11 | Python 3.12 |
|---|---|---|---|
| AWS Lambda, deprecation | Oct 31, 2026 | Jun 30, 2027 | Oct 31, 2028 |
| AWS Lambda, block create | Jul 29, 2027 | Jul 29, 2027 | Nov 30, 2028 |
| AWS Lambda, block update | Aug 31, 2027 | Aug 31, 2027 | Jan 10, 2029 |
| Google Cloud, deprecation | 2026-10-04 | 2027-10-24 | 2028-10-02 |
| Google Cloud, decommission | 2027-04-04 | 2028-04-24 | 2029-04-02 |
Lambda's numbers come from the AWS Lambda runtimes page, which also lists python3.13 and python3.14 at Jun 30, 2029 / Jul 31, 2029 / Aug 31, 2029. The Google Cloud dates are from Google Cloud's runtime support schedule, which puts 3.13 at 2029-10-10 deprecation and 2030-04-10 decommission.
Deprecation on Lambda has teeth. Per AWS, "After a runtime is deprecated, AWS may no longer apply security patches or updates to that runtime, and functions using that runtime are no longer eligible for technical support." You can still invoke functions: "While you can continue to invoke your functions indefinitely, AWS strongly recommends migrating to a supported runtime." Blocking creates and updates is the later, harder stop. On Google Cloud, "After the decommission date, you can no longer create new workloads or update existing workloads using the runtime." Google's 3.10 deprecation date already passed on 4 October.
Azure's Functions versions page lists Python 3.10 as generally available with end of support expected in October 2026, 3.11 in October 2027 and 3.12 in October 2028. It doesn't give a day. It also says "Python 3.12 is the last Python version supported for Linux Consumption plan apps," which matters if you planned to jump to 3.13 on that plan.
Look at the 3.11 column. Lambda deprecates python3.11 on Jun 30, 2027, four months before upstream's October 2027 end of life. A Lambda-heavy team that moves from 3.10 to 3.11 buys itself another migration inside a year.
How to plan the Python 3.10 upgrade
1. Inventory every place 3.10 runs
List services, Lambda and Cloud functions, Docker base images, CI jobs, data pipelines, scheduled tasks and developer tooling. The forgotten ones are often cron-style jobs and a base image three repos inherit from. Record the runtime and the owner for each.
2. Pick the target version
Choose 3.12 or later. That's judgment, not a vendor rule, and the reasoning is in the next sections. If you have a Django app, check the framework's floor first: the Django 6.1 support deadline piece covers why that release only supports Python 3.12 to 3.14.
3. Check dependency support
Pin the new version in a CI matrix next to 3.10 and run the full test suite on both. Failures on the new version point you at the packages that need bumping or replacing. Fix those before touching production.
4. Upgrade the lowest-risk service first
Start with an internal tool or a low-traffic service, ship it, and let it run for a few days. Then roll through the rest in order of risk, putting anything on a vendor deadline (Lambda functions before 31 October, for instance) ahead of anything that only has the upstream date.
5. Remove 3.10 and name an owner for stragglers
Drop 3.10 from the CI matrix and from base images once the last service moves. For anything that can't move yet, write down a date and one named owner. An exception without a date tends to stay forever.
What this means for your upgrade budget
Treat this as a scheduled project, not background maintenance. In our view, unpatched 3.10 is a standing risk from 1 October onward, so decide now how long you'll tolerate it, and set that limit on the calendar.
We would target 3.12 or later, not 3.11. 3.11 has about twelve months of upstream support left, and Lambda deprecates python3.11 on Jun 30, 2027. Moving to 3.11 can mean paying for the migration twice. 3.12 runs to October 2028 upstream and Lambda's matching date is Oct 31, 2028.
Reserve engineering time in proportion to how many services you found in the inventory, and name one person who owns the whole effort. Where that person doesn't exist on your team, hiring a Python engineer to own the upgrade is one way to fill it. For the next deadline on your list, see Platform and language release notes: what breaks and what to fix.
FAQ
Is Python 3.10 still safe to use?
In our judgment, not for anything exposed to untrusted input. The release page says 3.10.22 "does not receive security updates," so a vulnerability found tomorrow in ssl, tarfile or urllib.request stays unfixed on 3.10. Running it on an internal-only batch job is a lower risk, but still an open one.
Will my code stop working?
No. Existing code runs as it did. What stops is patching and support. On Lambda you can keep invoking functions after deprecation, but create and update get blocked on Jul 29, 2027 and Aug 31, 2027.
When does Lambda stop supporting Python 3.10?
The python3.10 runtime is deprecated on Oct 31, 2026. Blocking function creation starts Jul 29, 2027, and blocking updates starts Aug 31, 2027.
Should I upgrade to 3.11 or 3.12?
3.12, in our judgment. It's supported upstream through October 2028 against October 2027 for 3.11, and Lambda deprecates python3.11 on Jun 30, 2027. Teams that want a longer runway can go to 3.13 or 3.14, though Azure's Linux Consumption plan stops at 3.12. How Python compares with Go for a backend team is the better read if the upgrade has you questioning the language itself.
When does Python 3.11 reach end of life?
October 2027, per the devguide and the announcement post. Lambda's python3.11 runtime is deprecated earlier, on Jun 30, 2027.
