skip to navigation
skip to content

Planet Python

Last update: October 11, 2026 04:48 AM UTC

October 10, 2026


The Python Coding Stack

1. What makes an AI agent different from a chatbot?

Agents Unpacked • Chapter 1: Tools let a system act, but who chooses what happens next?

October 10, 2026 05:41 PM UTC

Stephen's Preface to Agents Unpacked

Real conversations about AI agents: what they are, how they work, and when they're useful

October 10, 2026 04:19 PM UTC

Agents Unpacked • Table of Contents

Conversations about what AI agents are, how they work, and when they're useful. No programming knowledge required.

October 10, 2026 12:42 PM UTC

October 09, 2026


Python Morsels

Python 3.15's best new features

Python 3.15 includes a UTF-8 default encoding, explicit lazy imports, * unpacking in comprehensions, a new sampling profiler, sentinel, frozendict, and more!

Table of contents

  1. A UTF-8 default encoding
  2. Sentinel objects
  3. Unpacking in comprehensions
  4. Explicit lazy imports
  5. The new profiling package
  6. Improved error messages
  7. More color!
  8. A few quick ones
  9. Try out Python 3.15 yourself

A UTF-8 default encoding

The best feature might be one of the most boring ones.

As of Python 3.15, UTF-8 is the default file encoding on all operating systems, which means... Windows.

Linux and Mac already used UTF-8 as their default file encoding in Python. But on Windows, Python used a legacy code page, which depended on your system's language settings. With English language settings, it was usually CP-1252.

Say a coworker on a Mac writes a file with an accented character in it:

>>> with open("cafe.txt", mode="wt") as f:
...     f.write("café")
...
4

What happens if we read that file from Python running on a Windows machine? Using the Windows default encoding of CP-1252, this is what we'd see:

>>> open("cafe.txt", encoding="cp1252").read()
'café'

We don't get an error... but we do get garbled text. UTF-8 stores é as two bytes, and CP-1252 happily reads those two bytes as two separate characters.

And if the file had an emoji in it, the old default encoding on Windows couldn't even write the file to begin with:

>>> with open("snake.txt", mode="wt", encoding="cp1252") as f:
...     f.write("🐍")
...
Traceback (most recent call last):
  File "<stdin>", line 2, in <module>
    f.write("🐍")
    ~~~~~~~^^^^^^
  File "/home/trey/.local/share/uv/python/cpython-3.15.0rc2-linux-x86_64-gnu/lib/python3.15/encodings/cp1252.py", line 19, in encode
    return codecs.charmap_encode(input,self.errors,encoding_table)[0]
           ~~~~~~~~~~~~~~~~~~~~~^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^^
UnicodeEncodeError: 'charmap' codec can't encode character '\U0001f40d' in position 0: character maps to <undefined>

In Python 3.15, the open function uses UTF-8 as its default encoding on every operating system, so a file written on one machine reads the same on every other machine.

If your code also needs to run on older versions of Python, it's still a good idea to explicitly pass encoding="utf-8" to the open function.

Sentinel objects

There's also now an official …

Read the full article: https://www.pythonmorsels.com/python315/

October 09, 2026 02:11 PM UTC


Rodrigo Girão Serrão

The 5 most exciting new features of Python 3.15

This article explains the 5 best new features of Python 3.15 with clear examples and explanations.

Python 3.15 has been published and it packs plenty of new features and improvements over Python 3.14. This article explores the five most exciting new features of Python 3.15:

  1. Lazy imports
  2. New built-in frozendict
  3. New built-in sentinel
  4. Unpacking inside comprehensions
  5. Tachyon, a new sampling profiler

You'll get the elevator pitch of each feature and you'll see a couple of examples of their usage.

By the end of this article you'll have a clear picture of some of the new cool features that Python 3.15 brings to the table and you'll be excited to try them out.

15 days of Python 3.15

To celebrate the release of Python 3.15, over the next 15 business days I'll be writing about a new 3.15 feature every day. Explained clearly and with examples so you don't have to sift through the changelog.

Subscribe to receive this free email series:

If you want, you can also check the schedule of the upcoming emails.

Lazy imports

Explicit lazy imports, introduced in PEP 810, introduce the new keyword lazy so that you can mark an import as lazy. Lazy imports don't run the module you're importing until the imported name is needed.

This feature is very useful if you have applications that have a slow startup time because they import heavy modules. For example, you can speed up the startup time of a CLI by lazy importing the dependencies of the CLI or the startup time of a development server that doesn't need to frontload every single dependency while you're debugging.

A lazy import starts with the...

October 09, 2026 12:15 PM UTC


Glyph Lefkowitz

Programming Isn’t Special

Artists understand that AI is bad for art. Why don’t programmers understand that we are artists?

October 09, 2026 07:00 AM UTC


Wingware

Wing Python IDE 12.1 Beta - October 9, 2026

Wing 12.1 is now available as a beta release. It introduces guided autonomous development. You specify the goals, answer questions, and review results. AI agents design and write the code, unit tests, and documentation. Wing keeps you in control. Wing Pro 12.1 now supports Claude Code, Codex, Antigravity, Copilot, Cursor, goose, OpenCode, and other ACP-compatible AI coding agents. It also adds a new Modern look and display themes, graphical revision control history, and many other improvements.

Wing 12.1 Screen Shot

Downloads

IMPORTANT Be sure to Check for Updates from Wing's Help menu after installing so that you have the latest hot fixes.

This is a beta release. Please try it and email us if you find problems or have suggestions!

Wing 12.1.0 -- Full-featured Python IDE with two licensing tiers

Wing 101 12.1.0 -- Free IDE for teaching beginners to program

Wing 12.1 will replace Wing 12.0 when it is installed. You can revert to Wing 12.0 by reinstalling it at any time.

To get started quickly with autonomous development in Wing 12.1, see Getting Started with Autonomous Development.

New in Wing 12.1

Autonomous Development with the Tasks Manager

The new Tasks Manager is an agent that runs the Tasks tool's queues for you, so that development proceeds autonomously under your direction. You write tasks, mark the ones you want started as Ready, and review the results.

The Manager accepts anything from a bug report to a high-level specification for a new software project. It can break down larger tasks into a design and development plan. It decides task order, serializes those that are likely to edit the same files, and runs closely related tasks in shared session context. It can message a running agent to tell it about related work or new insights, or redirect it if it goes astray.

While the Manager is on, tasks run autonomously: Rather than stopping to ask questions or present intermediate results, each works as far as it can and ends with a report of the judgement calls it made along the way, and any questions it has left. A new Questions tab in the Tasks tool collects everything that is waiting for you, so you can provide answers in one place. Follow-up work and problems that agents notice as they run are added to the Plan tab of the Tasks tool as new tasks. The Manager may automatically start found tasks that are closely related to ongoing work; others wait for your review.

You stay in control of which work runs, how much the Manager can do, and how results are reviewed. Every change the Manager makes is listed and can be reverted or revised, even after changes have been committed. You can also talk to the Manager to ask about the status of development or give it special instructions about your development workflow.

Claude Code and Codex are best for autonomous development, since they self-check the safety of commands that they run. Antigravity, Copilot, and Cursor also work but don't implement the same level of safety checks. See AI Agent Safety in the AI Agent-Assisted Development chapter of the manual in Wing 12.1's Help menu for details and safety recommendations.

The Manager agent itself and queues in the Tasks tool can each use a different agent. You bring your own subscriptions or API keys for the agents you choose. Wing does not install agents or provide access to models.

Other Improvements

Your Choice of AI Agent: Wing 12.1 adds support for other AI agents, now including Claude Code, Codex, Antigravity, Copilot, Cursor, goose, and OpenCode, either using their Textual User Interfaces (TUIs) or the Agent Client Protocol (ACP).

User Interface: An optional new Modern look redesigns the toolbar, Preferences dialog, status bar, and tab overflow, and improves the display font. A welcome window lets you choose what to open at startup. Two new display themes, Night Flight and Solo Flight, have been added. Themes can now incorporate transparent colors, be imported from VS Code, created from a small set of colors, or exported from your current color configuration.

Tasks Tool (Wing Pro): New Checklists hold recurring reviews, fixes, and release and deployment steps. A task's committed changes can now be reverted, edited, or commented on. Every task has a short ID that links to the task wherever it is cited, and mini-search works on every tab. Tracking of changes made by concurrently running tasks is more reliable, and there are many other fixes to task and session management.

Version Control (Wing Pro and Wing Classic): The git and mercurial logs now show a graphical history with expandable diffs, Project Log replaces Show Changeset, and the editor can show annotations with commit message tooltips.

Editor and Analysis: In all products, the editor's scroll bar shows marks for diffs, search matches, and errors and warnings. Source analysis is faster and its database is about 30% smaller.

Other Changes: Wing now offers to remove large cache directories left behind by older versions. Accept Debug Connections has moved to Project Properties so it is set per project. Wing 12.1 also includes many bug fixes, particularly for remote development and Docker containers, debugging free-threaded Python on Windows, git worktrees and submodules, non-ASCII text on Windows, unit test discovery, and display themes.

See the change log for details.

Getting Started with Autonomous Development

To get started quickly with autonomous development in Wing 12.1, see Getting Started with Autonomous Development.

If you have questions, please don't hesitate to contact us at support@wingware.com.

October 09, 2026 01:00 AM UTC


Python Insider

Python 3.15.0 (final) is here!

A brand new Python here for you to enjoy!

October 09, 2026 12:00 AM UTC


Core Dispatch

Core Dispatch #11

Welcome back to Core Dispatch! This edition covers August 27 through October 9, 2026 (It's been a while 😅). [Python 3.15.0 final](https://www.python.org/downloads/release/python-3150/) landed today after an extra release candidate for lazy-import blockers. Huge congrats to Hugo van Kemenade for gett

October 09, 2026 12:00 AM UTC

October 08, 2026


Anarcat

PSA: Europe changes time forward soon, North America next, for the last time?

This is a copy of an email I sent at work. I'm not sure I should be making noise about this here, feedback welcome.

This is your bi-yearly reminder that time is changing soon! October 25th in Europe, November 1st in North America. Less people in Canada are changing this year, with BC, Alberta, Manitoba and Northwest Territories getting rid of DST.

What's happening?

Some places in the world implement what is called Daylight saving time or DST:

https://en.wikipedia.org/wiki/Daylight_saving_time

Normally, you shouldn't have to do anything: computers automatically change time following local rules, assuming they are correctly configured, provided recent updates have been applied in the case of a recent change in said rules (because yes, this happens, and happened this year, and yes, you need to upgrade your software!).

Of course, appliances like your microwave oven will likely not change time and will need to adjusted unless they are so-called "smart", in which case they are part of the skynet botnet and should be destroyed.

If your clock is flashing "0:00" or "12:00", you have no action to take to adapt to this change, lucky you.

If you haven't changed time in six months, congratulations, your clock will be accurate again!

In any case, you should still consider DST because it might affect some of your meeting schedules, particularly if you set up a new meeting schedule in the last 6 months and forgot to consider this change.

If your location does not have DST

Properly scheduled meetings affecting multiple time zones are set in UTC time, which does not change. So if your location does not observer time changes, your (local!) meeting time will not change.

But be aware that some other folks attending your meeting might have the DST bug and their meeting times will change.

Be kind to those poor souls which might be missing meetings by a full hour because time flies backwards for them.

If you do observe DST

If you are affected by daylight savings, your local meeting times will change for UTC meetings. Normally, your meeting times are scheduled to take this into account and the new hours should be reasonable.

But now is a good time to verify that. Take a look at your schedule for the next couple of weeks and reschedule meetings before the daylight saving come up to avoid too much disruption. You have only a couple of weeks to do so right now.

When do times change, how, and and where?

As regular readers will remember, the rule of thumb is:

Spring forward, fall backwards.

That is, during the season of Spring, the clocks move forward, and during the Fall (like right now), they move backwards. That is in the northern hemisphere, but then the southern hemisphere is often saner and doesn't switch anyways.

So time will move backwards which means an extra hour of sleep. Unless you have children or bad sleep, in which case your body doesn't care about what the clock says and will wake up one hour earlier than what it should.

And of course, this doesn't happen everywhere at once, so let's see when it happens where.

Europe

The dance starts in Europe.

The change happens on the last Sunday in October at 01:00 UTC (not local time!), that is October 25th. If you are in the central European timezone, also known as Amsterdam, Berlin, or Paris time depending on your national affiliation, that essentially means that at 2:59 local the clocks will fall back to 2:00 instead of going to 3:00.

Concretely, set your watch back one hour before going to bed, go to bed at the normal time, and enjoy an extra hour of sleep or leisure.

If you have kids, you might want to start getting them to bed slightly earlier every day for a week before the change so they take time getting used to the change. If you have trouble sleeping in the morning, find your inner child and do that to yourself as well.

USA / Canada

Then it's the US[1] and Canada[2] joining the dance, on the First Sunday in November at 02:00 local (not UTC!), that is, I believe, November 1st 2026.

This means that, at 1:59, the clocks will flip to 1:00, instead of 2:00.

Concretely, do like the Europeans and tweak your clock before going to bed.

That is a little less than four weeks from now.

[1] except Arizona (except the Navajo nation), US territories, and Hawaii

[2] except Yukon, Saskatchewan, (newly) British Columbia, (newly) Alberta, (newly) Northwest Territories, (newly) Manitoba, one island in Nunavut (Southampton Island), one town in Ontario (Atikokan) and small parts of Quebec (Le Golfe-du-Saint-Laurent)

Other places with DST

This time again, I must apologize to the people of Cuba, Lebanon, Israel, Palestine, Egypt, Chile, Australia, and New Zealand, as you fine folks all have your own DST rules that are omitted here for brevity. I rely on this page from Wikipedia to be updated by time nerds accurately for this message, and it should provide you with a rough idea of what's coming:

https://en.wikipedia.org/wiki/Daylight_saving_time_by_country

In general, changes also happen in October, but either on different times or different days, except in the south hemisphere, where they might happen in September (oops, sorry NZ folks, I'm late!).

Places without DST

Everyone else, enjoy, you're on the right side of history, and we thank you for the good example you give us.

Changes since last time

There's been lots of changes since last time:

This is my interpretation of the changes announced on the tzdata mailing list here:

https://lists.iana.org/hyperkitty/list/tz-announce@iana.org/latest

If the eastward trend continues, Canada should adopt country-wide "no daylight savings" rules by 2027, although there's actually no sign of the other provinces (Ontario, Québec and so on) currently running bills to change those rules just yet. Poor Canadians like me confused about time in their countries can refer to this section of Wikipedia for details:

https://en.wikipedia.org/wiki/Daylight_saving_time_in_Canada#By_province_and_territory

... and particularly the image featured there:

https://commons.wikimedia.org/wiki/File:Canada_time_zone_map-en.svg

It also seems like the US government might finally adopt a permanent daylight saving change bill in 2026, as the "Sunshine protection act" pass the house in July:

https://en.wikipedia.org/wiki/Sunshine_Protection_Act

True to form, this was associated with absolutely ridiculous pressure from Donald Trump against republicans (his own party!) objecting to the change:

On July 14, 2026, the House passed a Sunshine Protection Act bill backed by President Trump. Nevertheless, the bill was opposed in the Senate by Republicans, including Senator Cotton. In response, on October 3, 2026, Trump shared a post on Truth Social urging Cotton to approve the bill, where he revealed Cotton's personal cellphone number and called on people to call him.

https://www.theguardian.com/us-news/2026/oct/03/trump-tom-cotton-daylight-saving-time

Given that the last time the US did a major change to the daylight savings policy (in 2005), Canada followed suit to stay in sync, it's quite possible Trump's mad dash might actually finish getting rid of DST in North America:

https://en.wikipedia.org/wiki/Energy_Policy_Act_of_2005#Change_to_daylight_saving_time

October 08, 2026 07:30 PM UTC


Django Weblog

Django security reporting update

We are no longer accepting new security reports for the Django project through HackerOne. Existing reports submitted through HackerOne will remain open and continue to be handled by the Django Security Team.

If you discover a security issue in Django, please follow the reporting process described in the Django security policies.

Security issues should be reported by emailing security@djangoproject.com

October 08, 2026 11:00 AM UTC


Eli Bendersky

Monte-Carlo simulations

Monte Carlo simulations (or methods) is the technique of applying randomness and the Law of large numbers to the solution of various scientific and engineering problems. One of its first documented uses was by Stanislaw Ulam and John von Neumann for nuclear weapon simulations after WWII [1].

In this post …

October 08, 2026 09:35 AM UTC

October 07, 2026


LernerPython blog, from Reuven Lerner

Pandas groupby with two columns: Reshape results with unstack

Invoke “groupby” with two categorical columns in Python Pandas, and get a two-part multi-index: Turn into a data frame with unstack:

The post Pandas groupby with two columns: Reshape results with unstack appeared first on LernerPython.

October 07, 2026 06:00 AM UTC


Python GUIs

Change the color of the ProgressBar indicator text when it exceeds 50%

How can I change the text color from black to white of the percentage indicator inside the QProgressBar when it exceeds the value of 50?

October 07, 2026 06:00 AM UTC

Using Complex Data Sources with PyQt6 Model/View Architecture — How to use JSON, nested data, and other complex structures in your Qt table and list views

I have a complex data set in a JSON file. Is it possible to use this as my model's data in PyQt6 views, or do I need to simplify it to a basic table?

October 07, 2026 06:00 AM UTC

October 06, 2026


Python Bytes

#499 So many questions??

Topics include PEP 824 brings ?? and ??= to Python for None handling, Python 3.15 Python 3.10, asyncio.shield, and Pyxel: the retro game engine for Python.

October 06, 2026 11:16 PM UTC


PyCoder’s Weekly

Issue #755: 3.15 Gets an RC3, New Feature Rundown, Sampling Profiler, and More (2026-10-06)

October 06, 2026 07:30 PM UTC


Tryton News

Tryton Release 8.2

We are proud to announce the 8.2 release of Tryton.
This release provides many bug fixes, performance improvements and some fine tuning.
You can give it a try on the demo server, use the docker image or download it here.
As usual upgrading from previous series is fully supported.

Here is a list of the most noticeable changes:

Changes for the User

Client

When deleting or removing multiple rows from a list widget, a popup is displayed to confirm the selection that will be deleted or removed.
And when clicking on delete or remove from a list widget with no row selected, a search popup is raised to search and select the rows to delete or remove.

When selecting multiple rows for editing from a One2Many widget, the edition popup loops over each record. This is a faster and more reliable way to perform a mass edition.

The login services can now display an icon to represent the service provider. This makes it easier for users to select the right services.

The Binary widget supports filtering the file selection per file extension and mime type.
And when the field has no file name defined, the widget will use the record name as a fallback file name when the content is downloaded.

It is now possible to mark as read a set of notifications.

Accounting

The “Open Journal” menu entry has been replaced by the “Lines” menu entry which uses a journal and period header as default values.
This new menu entry also provides a new way to search for accounting lines.

We now use the maturity date before the effective date to calculate the reconciliation date.

The wizard to create dunning allows limiting the creation to a selection of companies.

The wizard to create direct debits allows limiting the creation to a selection of companies.

When posting an invoice, the system will check the validity of the European tax identifiers used.

A relate is now available from the period and the fiscal year to open the related invoices.
This is useful when you need to collect all the invoices done in a period, for example to send to an external accountant.

The SEPA payment module now includes the flavors pain.001.001.09 and pain.008.001.08.

A generic CSV format has been added to import statements. You can configure the format to map columns to the Tryton fields.
It is common that banks provide only a custom CSV format for the statements.

It is now possible to create tax rules based on organizations.
This is useful for example to create a single rule that applies to all European countries.

E-document

PEPPOL

We added a configurable processing delay on each PEPPOL service.
This prevents sending the newly posted invoice directly and allows some time for the user to correct any mistakes.

UN/CEFACT

Tryton can now parse the UN/CEFACT invoice to create a supplier invoice.
This will be useful to implement French e-invoicing.

Party

The wizard to check VAT numbers with the VIES service has been replaced by an automatic background task.
Once a number has been validated, it is considered valid for a configurable period before being re-validated.

When entering a contact mechanism, the system will try to guess the type.

Product

The products can now be added or removed directly from the category form.

Production

A tolerance can now be configured on each BoM. It raises warnings when the input or output quantities deviate from the calculated quantities from the BoM. It also detects additional or missing products.

Purchase

Tryton now calculates the actual average lead time of each product supplier over the last year.
This is useful to update the configured lead time or to find poor suppliers.

Sales

It is now possible to configure sales to create customer shipments only in draft (instead of waiting).
This is useful when the workflow requires a manual validation of the shipment before being processed.

The wizard to create invoices and consumptions of subscriptions allows limiting the creation to a selection of companies.

A stock lot can now be set on the sale line from a POS.
This is useful for businesses that require tracking the lot sold to customers.

Stock

Tryton now warns when an inventory modifies the quantities or costs too much.
The variations are now displayed with a visual hint when they are close to the tolerance.

A scheduled task has been added to create stock periods automatically using a configured interval. And another task closes them after a configured delay.
This removes the need to manually close stock periods, which is important for performance.

Web Shop

A scheduled task has been added to cancel abandoned sales after a configured delay per web shop.
This prevents the list of draft sales from increasing too much.

New Modules

Account Invoice Factur-X

The Account Invoice Factur-X Module allows to generate invoices in Factur-X format.

Document Incoming OCR Eagle Doc

The Document Incoming OCR Eagle Doc Module provides integration with Eagle Doc services.

Project Disbursement

The Project Disbursement Module provides support for paying and invoicing disbursements per project.

Stock Conversion

The Stock Conversion Module transforms one product into another with ease.

Changes for the System Administrator

Server

The “Administration” group has been replaced by an “Administrator” flag on the user.
This ensures that an administrator always has access to everything even if a resource access is restricted to a group (which was not the “Administration” group).

The trytond-admin command can now manage any user. This means that it can create a new user, activate or deactivate, promote as administrator or demote from administrator, set the email or password and send a reset password email.

The unfinished queued tasks are now retried automatically by a scheduled task.

A timer is now attached to every RPC request with a timeout defined. It ensures that the request does not last longer by raising a TimeOutException.

:warning: The webhooks must be updated to include the /r/ prefix inherited from the new Router.
We have kept the former routes for backward compatibility.

Accounting

The Stripe API has been updated to the version 2026-09-30.endive.

Stock

The DPD Shipment Service API has been updated to version 4.5.

Changes for the Developer

Server

The readonly attribute and states are now enforced on the server-side when checking the access rights of the user.

The fields have a new editable states which completes the existing readonly but it is not enforced, only used for UI purposes.

We added BulkBuffer for creation, deletion, save or any function on ModelStorage.
The BulkBuffers are context managers that are flushed when reaching a defined size by calling a function with the current content.
This is useful when looping on a large set of records to limit the memory consumption.
Ex:

# records are saved every 2000 records
with Model.bulk_save() as save:
    for record in records:
         record.amount += 10
         save.push(record)

A new router type of object is now supported in the Pool.
A Router exposes entrypoints but as it is registered in the Pool it can be extended by other modules.
The entrypoint of a Router is only registered for the database for which the origin module is activated.

A route has been added for the custom.js and custom.css files of sao. It chains a list of files that can be extended by any module.

The ORM is now using a BrowseList instead of a simple list of instances. The BrowseList allows keeping the cache and prefetching aligned with its content when it is mutated, for example by .sort().

It is now possible to define the filename extension of Binary fields.
And it is also possible to set filters on the binary and image widgets.

The database connection cursor now supports row factories like dict_row, namedtuple_row and scalar_row. They change the default tuple type of fetched records.
Thanks to the row factory, the cursor_dict has been removed.

It is now possible to configure Mixins to apply to the Database and TableHandler of the backend.
This feature is now used for the GIS backend.

We added support for AGE to the SQLite backend.

The DBTestCase is now public and can be reused by modules. It is useful to create test cases based on a module but without the generic tests from ModuleTestCase.

The XML record tag now supports a search attribute. The value is a domain used to search for existing records and reuse them when the id is not yet known.
This is useful for example to create a country record which may have been already created.

The convert module gains an import_xml function which can be used to import XML files into the database (like the file declared in the module).
It can be useful for tests that need to have such records created.

The email validation tools now have a check deliverability option.

The URLAccessor can now accept a request parameter to use instead of the Transaction.context.

The ResourceAccessMixin gains two new fields last_user and last_modification.

Proteus the scripting client

When configured with trytond (on the server host), it allows controlling access checks with the _check_access contextual keyword.

Company

The companies and employees are now in the user context.
This is useful to write domains that restrict a selection to only allowed companies or employees.

1 post - 1 participant

Read full topic

October 06, 2026 04:00 PM UTC


Django Weblog

Django security releases issued: 6.1.2, 6.0.9, and 5.2.18

In accordance with our security release policy, the Django team is issuing releases for Django 6.1.2, Django 6.0.9, and Django 5.2.18. These releases address the security issues detailed below. We encourage all users of Django to upgrade as soon as possible.

CVE-2026-77050: Potential denial-of-service vulnerability in get_supported_language_variant()

django.utils.translation.get_supported_language_variant() was subject to a potential denial-of-service attack when processing many distinct, very long language codes. Language codes were used as keys in an in-memory cache before their length was limited, potentially consuming excessive process memory.

To mitigate this vulnerability, language codes longer than 500 characters are now rejected or truncated before the cached lookup.

This issue has severity "low" according to the Django security policy.

Thanks to Gleb Lizunov for the report.

CVE-2026-84429: Potential denial-of-service vulnerability in HTTP header parsing

django.utils.http.parse_header_parameters() was subject to a potential denial-of-service attack due to quadratic time complexity when parsing a value with many separators inside a quoted parameter. An unauthenticated request could reach this parsing through headers such as Accept or Content-Type, for instance via the content negotiation performed by HttpRequest.accepts(). The per-call length limit does not bound the combined size of repeated headers.

The undocumented django.utils.http.parse_header_parameters() function now uses Python's email.message.Message for parsing. As a result, parsing of some malformed or unusual header values may differ, for example, RFC 2231 values with a missing encoding are now decoded.

This issue has severity "moderate" according to the Django security policy.

Thanks to Jisung Chae for the report.

CVE-2026-87890: Potential request forgery via spatial lookup byte values

Spatial lookups accepted raster values provided as bytes without requiring them to be explicitly wrapped in django.contrib.gis.gdal.GDALRaster. Although these values were opened through GDAL's in-memory virtual filesystem, they could contain a VRT document referencing an external raster source. This could cause GDAL to issue network requests as the Django process user while preparing the lookup.

This issue could be exploited by applications that passed attacker-controlled bytes directly to a spatial lookup. It was overlooked in the fix for CVE-2026-15307.

To mitigate this issue, raster values provided as bytes must now be wrapped in GDALRaster before being used in spatial lookups. Byte values representing valid hexadecimal geometries remain accepted.

This is a backward incompatible change. As a reminder, all untrusted user input should be validated before use.

This issue has severity "moderate" according to the Django security policy.

Thanks to sicksec for the report.

CVE-2026-87975: Privilege abuse in model formsets with editable primary keys

Model formsets incorrectly allowed forged POST data to either delete instances outside the limiting queryset or create instances via edit-only formsets when the model's primary key could be set through the form, such as with: a OneToOneField (or parent link used as the primary key of an inline formset's model), or a natural or UUID primary key included in the form's fields. Models using the default BigAutoField primary key were not affected.

This issue has severity "moderate" according to the Django security policy.

Thanks to Seonggwon Yoon for the report.

Affected supported versions

Resolution

Patches to resolve the issue have been applied to Django's main, 6.1, 6.0, and 5.2 branches. The patches may be obtained from the following changesets.

CVE-2026-77050: Potential denial-of-service vulnerability in get_supported_language_variant()

CVE-2026-84429: Potential denial-of-service vulnerability in HTTP header parsing

CVE-2026-87890: Potential request forgery via spatial lookup byte values

CVE-2026-87975: Privilege abuse in model formsets with editable primary keys

The following releases have been issued

The PGP key ID used for this release is Sarah Boyce: 3955B19851EA96EF

General notes regarding security reporting

As always, we ask that potential security issues be reported via private email to security@djangoproject.com, and not via Django's Trac instance, nor via the Django Forum. Please see our security policies for further information.

October 06, 2026 01:00 PM UTC


LernerPython blog, from Reuven Lerner

Pandas groupby with sort=False: Keep groups in order of appearance

A “groupby” call in Python Pandas is normally sorted by index. But if you’re grouping by month name, April will come before January. Pass “sort=False”, and the index will reflect […]

The post Pandas groupby with sort=False: Keep groups in order of appearance appeared first on LernerPython.

October 06, 2026 06:00 AM UTC


Armin Ronacher

What is Codemode

October 06, 2026 12:00 AM UTC

October 05, 2026


Tryton News

Security Release for issue 15032

Jaisurya has discovered that the content of the HTML editor was not escaped.

Impact

CVSS v3.0 Base Score: 5.4

Workaround

Setup restrictive CSP without unsafe inline script may prevent the attack.

Resolution

All affected users should upgrade trytond to the latest version.

Affected versions per series:

Not affected versions per series:

Reference

Concerns?

Any security concerns should be reported on the bug-tracker at https://bugs.tryton.org/ with the confidential checkbox checked.

1 post - 1 participant

Read full topic

October 05, 2026 06:00 AM UTC

Security Release for issue 15035

lizparadox_ has discovered that the report name can be used to execute commands on the server.

Impact

CVSS v3.0 Base Score: 6.8

Workaround

There is no workaround.

Resolution

All affected users should upgrade trytond to the latest version.

Affected versions per series:

Not affected versions per series:

Reference

Concerns?

Any security concerns should be reported on the bug-tracker at https://bugs.tryton.org/ with the confidential checkbox checked.

1 post - 1 participant

Read full topic

October 05, 2026 06:00 AM UTC


LernerPython blog, from Reuven Lerner

Pandas groupby basics: Aggregating a numeric column by category

The simplest grouping in Python Pandas is groupby: For example: Returns a series whose index is the unique values from passenger_count.

The post Pandas groupby basics: Aggregating a numeric column by category appeared first on LernerPython.

October 05, 2026 06:00 AM UTC

October 04, 2026


Mark Dufour

Shed Skin v0.9.14, v1.0 coming soon!

October 04, 2026 11:29 AM UTC