“the (unverified) reference implementation of SHA3 was hit with a bad CVE in 2022, which Python “inherited”, because it vendored that very same SHA3 implementation.”
Python’s hashlib now uses formally verified code for every default hash. It took two and a half years and 15,000 lines. Python had shipped unverified SHA3 code and inherited its 2022 CVE. This fixes the cause instead of the symptom.