Mailman 3 python.org
Sign In Sign Up
Manage this list Sign In Sign Up

Keyboard Shortcuts

Thread View

  • j: Next unread message
  • k: Previous unread message
  • j a: Jump to all threads
  • j l: Jump to MailingList overview

Security-announce

Download
Threads by month
  • ----- 2026 -----
  • February
  • January
  • ----- 2025 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2024 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2023 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2022 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2021 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2020 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2019 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2018 -----
  • December
  • November
  • October
  • September
  • August
  • July
  • June
  • May
  • April
  • March
  • February
  • January
  • ----- 2017 -----
  • December
  • November
  • October
  • September
security-announce@python.org

August 2025

  • 2 participants
  • 1 discussions
Windows code signing certificates for Python 3.12.8, 3.13.1 revoked
by Seth Larson Aug. 29, 2025

Aug. 29, 2025
We have been made aware that the code signing certificates used for our 3.12.8 and 3.13.1 releases on Windows may have been used to sign malicious code. As a precautionary measure, the certificate has been revoked, which may result in Windows warning about or refusing to execute these versions of Python. Additionally we’ve rotated all secrets related to code signing for Windows. At this point there is also no indication that CPython build infrastructure or signing has been compromised after auditing the artifacts and build processes for the mentioned Python releases. Our signing infrastructure generates new certificates frequently, and so these are the only affected releases (see the explanation at the end of https://www.python.org/downloads/). There are no known issues with those releases, but the certificate has been revoked to help reduce the risk of malicious code hiding behind our reputation. As a workaround, we suggest updating to 3.12.10 or 3.13.7. At this stage, no further information is available, and the investigation into whether, and how, our certificate was misused is ongoing. We were already following secure practices for handling code signing certificates, and have taken additional steps to ensure that our infrastructure is not persistently compromised. We will provide updates on this thread as they become available. Please see the thread on discuss.python.org for more information or if you have questions: https://discuss.python.org/t/windows-code-signing-certificates-for-python-3…
2 1
0 0

HyperKitty Powered by HyperKitty version 1.3.12.