What changed in cryptography from 49 to 50
2 releases numbered after 49.0.0 up to and including 50.0.1, stable releases only. 49.0.0 and 50.0.1 are the newest stable releases of 49 and 50 we track; this page follows them as new ones ship.
- 1 CVE mentioned
- 1 removes or deprecates something
16 changes across 2 releases
Added 4
- Added xof() class methods to SHAKE128 and SHAKE256 for constructing algorithm instances configured for use with XOFHash
- Added the Cobblestone (streaming symmetric encryption) recipe, an implementation of the Cobblestone-128 and Cobblestone-256 instantiations of the C2SP chunked-encryption specification for streaming authenticated encryption of large messages
- Added support for using Name as a field type in the ASN.1 module
- Added MLDSAMuHasher for incrementally computing the ML-DSA mu (message representative) used by the external-mu signing and verification APIs
Changed 5
- X.509 verification APIs are now considered stable and are subject to the API stability policy
- XOFHash is now supported when building against AWS-LC
- HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported when building against AWS-LC
- Diffie-Hellman key exchange is now supported when building against AWS-LC
- The builtin HashAlgorithm classes and the classes in padding can now be compared with ==
Fixed 5
- Parsing a Signed Certificate Timestamp list now rejects encodings that carry trailing bytes after the list or after an individual SCT
- Loading a public key or an EC private key now rejects DER where the subjectPublicKey (or EC publicKey) BIT STRING declares a non-zero number of unused bits
- Parsing a CRL entry's InvalidityDate extension now rejects a GeneralizedTime that carries fractional seconds or another non-DER form
- load_der_ocsp_request() and load_der_ocsp_response() now reject a request or response whose version field is not v1, the only version defined by RFC 6960
- load_der_public_key() and load_pem_public_key() now reject Diffie-Hellman public keys whose modulus is smaller than 512 bits
Deprecated 1
- Diffie-Hellman key exchange over finite fields (FFDH) is deprecated, including the types in cryptography.hazmat.primitives.asymmetric.dh and loading FFDH keys or parameters with the key loading APIs
Security 1
- pkcs7_decrypt_der() and its PEM and S/MIME variants no longer expose distinguishable errors or timing when unwrapping a RecipientInfo's encryptedKey, which could act as a Bleichenbacher oracle for callers that decrypt untrusted messages, by substituting a random key on failure as described in RFC 3218
One release in the range carries no categorized changes yet: 50.0.1. Their original notes, where the vendor published any, are below.
Original release notes, newest first
The list above is our reading of these notes; the originals from cryptography are here, one fold per release.
50.0.1
- Updated Windows, macOS, and Linux wheels to be compiled with OpenSSL 4.0.2.
50.0.0
- SECURITY ISSUE: pkcs7_decrypt_der()and its PEM and S/MIME variants no longer expose distinguishable errors or timing when unwrapping a
RecipientInfo’sencryptedKey, which could act as a Bleichenbacher oracle for callers that decrypt untrusted messages. A random key is now substituted on failure, as described in RFC 3218. Credit to @X1AOxiang for reporting the issue. CVE-2026-69247 - Deprecated Diffie-Hellman key exchange over finite fields (FFDH). Everything FFDH is deprecated, including the types in
cryptography.hazmat.primitives.asymmetric.dhand loading FFDH keys or parameters with the key loading APIs. Users should migrate to a more modern key exchange algorithm. - Added
xof()class methods to SHAKE128 and SHAKE256 for constructing algorithm instances configured for use with XOFHash. - The X.509 verification APIs are now considered stable and are subject to our API stability policy.
- Added the Cobblestone (streaming symmetric encryption) recipe, an implementation of the Cobblestone-128 and Cobblestone-256 instantiations of the C2SP chunked-encryption specification for streaming authenticated encryption of large messages.
- Parsing a Signed Certificate Timestamp list now rejects encodings that carry trailing bytes after the list or after an individual SCT, instead of silently ignoring them.
- Added support for using Name as a field type in the ASN.1 module.
- Loading a public key or an EC private key now rejects DER where the
subjectPublicKey(or ECpublicKey)BIT STRINGdeclares a non-zero number of unused bits, instead of silently ignoring it. - Parsing a CRL entry’s
InvalidityDateextension now rejects aGeneralizedTimethat carries fractional seconds or another non-DER form, matching the strict encoding already required for every other X.509 time field. - load_der_ocsp_request() and load_der_ocsp_response() now reject a request or response whose
versionfield is notv1, the only version defined by RFC 6960, matching the version validation already performed when loading certificates, CSRs and CRLs. - XOFHash is now supported when building against AWS-LC.
- HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported when building against AWS-LC.
- Diffie-Hellman (Diffie-Hellman key exchange) is now supported when building against AWS-LC.
- load_der_public_key() and load_pem_public_key() now reject Diffie-Hellman public keys whose modulus is smaller than 512 bits, matching the minimum already enforced when loading DH private keys and when constructing DHParameterNumbers.
- Added MLDSAMuHasher for incrementally computing the ML-DSA
mu(message representative) used by the external-mu signing and verification APIs. - The builtin HashAlgorithmclasses and the classes in padding can now be compared with
==. - CertificateBuilder now supports creating unsigned certificates (RFC 9925) with the
create_unsignedmethod. - The X.509 verification APIs now permit ML-DSA-44, ML-DSA-65, and ML-DSA-87 (RFC 9881) public keys and signatures by default.