What changed in cryptography from 49 to 50

2 releases numbered after 49.0.0 up to and including 50.0.1, stable releases only. 49.0.0 and 50.0.1 are the newest stable releases of 49 and 50 we track; this page follows them as new ones ship.

16 changes across 2 releases

Added 4

50.0.0

  • Added xof() class methods to SHAKE128 and SHAKE256 for constructing algorithm instances configured for use with XOFHash
  • Added the Cobblestone (streaming symmetric encryption) recipe, an implementation of the Cobblestone-128 and Cobblestone-256 instantiations of the C2SP chunked-encryption specification for streaming authenticated encryption of large messages
  • Added support for using Name as a field type in the ASN.1 module
  • Added MLDSAMuHasher for incrementally computing the ML-DSA mu (message representative) used by the external-mu signing and verification APIs
Changed 5

50.0.0

  • X.509 verification APIs are now considered stable and are subject to the API stability policy
  • XOFHash is now supported when building against AWS-LC
  • HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported when building against AWS-LC
  • Diffie-Hellman key exchange is now supported when building against AWS-LC
  • The builtin HashAlgorithm classes and the classes in padding can now be compared with ==
Fixed 5

50.0.0

  • Parsing a Signed Certificate Timestamp list now rejects encodings that carry trailing bytes after the list or after an individual SCT
  • Loading a public key or an EC private key now rejects DER where the subjectPublicKey (or EC publicKey) BIT STRING declares a non-zero number of unused bits
  • Parsing a CRL entry's InvalidityDate extension now rejects a GeneralizedTime that carries fractional seconds or another non-DER form
  • load_der_ocsp_request() and load_der_ocsp_response() now reject a request or response whose version field is not v1, the only version defined by RFC 6960
  • load_der_public_key() and load_pem_public_key() now reject Diffie-Hellman public keys whose modulus is smaller than 512 bits
Deprecated 1

50.0.0

  • Diffie-Hellman key exchange over finite fields (FFDH) is deprecated, including the types in cryptography.hazmat.primitives.asymmetric.dh and loading FFDH keys or parameters with the key loading APIs
Security 1

50.0.0

  • pkcs7_decrypt_der() and its PEM and S/MIME variants no longer expose distinguishable errors or timing when unwrapping a RecipientInfo's encryptedKey, which could act as a Bleichenbacher oracle for callers that decrypt untrusted messages, by substituting a random key on failure as described in RFC 3218

One release in the range carries no categorized changes yet: 50.0.1. Their original notes, where the vendor published any, are below.

Original release notes, newest first

The list above is our reading of these notes; the originals from cryptography are here, one fold per release.

50.0.1
  • Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.2.

View originalPermalink

50.0.0
  • SECURITY ISSUE: pkcs7_decrypt_der()and its PEM and S/MIME variants no longer expose distinguishable errors or timing when unwrapping a RecipientInfo’s encryptedKey, which could act as a Bleichenbacher oracle for callers that decrypt untrusted messages. A random key is now substituted on failure, as described in RFC 3218. Credit to @X1AOxiang for reporting the issue. CVE-2026-69247
  • Deprecated Diffie-Hellman key exchange over finite fields (FFDH). Everything FFDH is deprecated, including the types in cryptography.hazmat.primitives.asymmetric.dh and loading FFDH keys or parameters with the key loading APIs. Users should migrate to a more modern key exchange algorithm.
  • Added xof() class methods to SHAKE128 and SHAKE256 for constructing algorithm instances configured for use with XOFHash.
  • The X.509 verification APIs are now considered stable and are subject to our API stability policy.
  • Added the Cobblestone (streaming symmetric encryption) recipe, an implementation of the Cobblestone-128 and Cobblestone-256 instantiations of the C2SP chunked-encryption specification for streaming authenticated encryption of large messages.
  • Parsing a Signed Certificate Timestamp list now rejects encodings that carry trailing bytes after the list or after an individual SCT, instead of silently ignoring them.
  • Added support for using Name as a field type in the ASN.1 module.
  • Loading a public key or an EC private key now rejects DER where the subjectPublicKey (or EC publicKey) BIT STRING declares a non-zero number of unused bits, instead of silently ignoring it.
  • Parsing a CRL entry’s InvalidityDate extension now rejects a GeneralizedTime that carries fractional seconds or another non-DER form, matching the strict encoding already required for every other X.509 time field.
  • load_der_ocsp_request() and load_der_ocsp_response() now reject a request or response whose version field is not v1, the only version defined by RFC 6960, matching the version validation already performed when loading certificates, CSRs and CRLs.
  • XOFHash is now supported when building against AWS-LC.
  • HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported when building against AWS-LC.
  • Diffie-Hellman (Diffie-Hellman key exchange) is now supported when building against AWS-LC.
  • load_der_public_key() and load_pem_public_key() now reject Diffie-Hellman public keys whose modulus is smaller than 512 bits, matching the minimum already enforced when loading DH private keys and when constructing DHParameterNumbers.
  • Added MLDSAMuHasher for incrementally computing the ML-DSA mu (message representative) used by the external-mu signing and verification APIs.
  • The builtin HashAlgorithmclasses and the classes in padding can now be compared with ==.
  • CertificateBuilder now supports creating unsigned certificates (RFC 9925) with the create_unsigned method.
  • The X.509 verification APIs now permit ML-DSA-44, ML-DSA-65, and ML-DSA-87 (RFC 9881) public keys and signatures by default.

View originalPermalink