Aug. 24, 2023, 8:56 p.m. | Łukasz Langa (noreply@blogger.com)

Python Insider pythoninsider.blogspot.com

There’s security content in the releases, let’s dive right in.


  • gh-108310: Fixed an issue where instances of ssl.SSLSocket
    were vulnerable to a bypass of the TLS handshake and included
    protections (like certificate verification) and treating sent
    unencrypted data as if it were post-handshake TLS encrypted data.
    Security issue reported as CVE-2023-40217 1 by Aapo Oksman. Patch by Gregory P. Smith.

Upgrading is highly recommended to all users of affected versions.


Python 3.11.5


Get it here: https://www.python.org/downloads/release/python-3115/

This release was …

data encrypted data instances issue python python 3 releases security ssl tls verification vulnerable

Founding AI Engineer, Agents

@ Occam AI | New York

AI Engineer Intern, Agents

@ Occam AI | US

AI Research Scientist

@ Vara | Berlin, Germany and Remote

Data Architect

@ University of Texas at Austin | Austin, TX

Data ETL Engineer

@ University of Texas at Austin | Austin, TX

Lead GNSS Data Scientist

@ Lurra Systems | Melbourne