Skip to content

chore(deps): bump cryptography from 49.0.0 to 50.0.0 - #1086

Merged
frankbria merged 1 commit into
mainfrom
dependabot/uv/cryptography-50.0.0
Aug 10, 2026
Merged

chore(deps): bump cryptography from 49.0.0 to 50.0.0#1086
frankbria merged 1 commit into
mainfrom
dependabot/uv/cryptography-50.0.0

Conversation

@dependabot

@dependabot dependabot Bot commented on behalf of github Aug 5, 2026

Copy link
Copy Markdown
Contributor

Bumps cryptography from 49.0.0 to 50.0.0.

Changelog

Sourced from cryptography's changelog.

50.0.0 - 2026-07-31


* **SECURITY ISSUE**:
  :func:`~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der`
  and its PEM and S/MIME variants no longer expose distinguishable errors or
  timing when unwrapping a ``RecipientInfo``'s ``encryptedKey``, which could
  act as a Bleichenbacher oracle for callers that decrypt untrusted messages.
  A random key is now substituted on failure, as described in :rfc:`3218`.
  Credit to **@X1AOxiang** for reporting the issue. **CVE-2026-69247**
* Deprecated Diffie-Hellman key exchange over finite fields (FFDH).
  Everything FFDH is deprecated, including the types in
  ``cryptography.hazmat.primitives.asymmetric.dh`` and loading FFDH keys or
  parameters with the key loading APIs. Users should migrate to a more
  modern key exchange algorithm.
* Added ``xof()`` class methods to
  :class:`~cryptography.hazmat.primitives.hashes.SHAKE128` and
  :class:`~cryptography.hazmat.primitives.hashes.SHAKE256` for constructing
  algorithm instances configured for use with
  :class:`~cryptography.hazmat.primitives.hashes.XOFHash`.
* The :mod:`X.509 verification <cryptography.x509.verification>` APIs are now
  considered stable and are subject to our API stability policy.
* Added the :doc:`/cobblestone` recipe, an implementation of the
  Cobblestone-128 and Cobblestone-256 instantiations of the `C2SP
  chunked-encryption specification
  <https://c2sp.org/chunked-encryption>`_ for streaming authenticated
  encryption of large messages.
* Parsing a Signed Certificate Timestamp list now rejects encodings that
  carry trailing bytes after the list or after an individual SCT, instead of
  silently ignoring them.
* Added support for using :class:`~cryptography.x509.Name` as a field type in
  the :doc:`/hazmat/asn1/index` module.
* Loading a public key or an EC private key now rejects DER where the
  ``subjectPublicKey`` (or EC ``publicKey``) ``BIT STRING`` declares a non-zero
  number of unused bits, instead of silently ignoring it.
* Parsing a CRL entry's ``InvalidityDate`` extension now rejects a
  ``GeneralizedTime`` that carries fractional seconds or another non-DER form,
  matching the strict encoding already required for every other X.509 time
  field.
* :func:`~cryptography.x509.ocsp.load_der_ocsp_request` and
  :func:`~cryptography.x509.ocsp.load_der_ocsp_response` now reject a request
  or response whose ``version`` field is not ``v1``, the only version defined
  by RFC 6960, matching the version validation already performed when loading
  certificates, CSRs and CRLs.
* :class:`~cryptography.hazmat.primitives.hashes.XOFHash` is now supported
  when building against AWS-LC.
* HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported when
  building against AWS-LC.
* Diffie-Hellman (:doc:`/hazmat/primitives/asymmetric/dh`) is now supported
  when building against AWS-LC.
</tr></table> 

... (truncated)

Commits

@dependabot dependabot Bot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Aug 5, 2026
@frankbria

Copy link
Copy Markdown
Owner

Dependabot Triage — PR #1086: cryptography 49.0.0 → 50.0.0

Classification

  • Update type: Security update (major version bump)
  • Security urgency: High
  • Supply-chain risk: Medium (major bump — API-break risk, not supply-chain suspicion)

Key observations

  • Verified GHSA-g6cj-pr64-35w5 (high, CVE-2026-69247): PKCS#7 EnvelopedData decryption exposes a Bleichenbacher oracle through distinguishable errors and timing.
  • Vulnerable range >= 44.0.0, < 50.0.0; the repo is on 49.0.0, so it is affected. First patched version is exactly 50.0.0 — this bump is the only fix available.
  • Major-version jump, so the risk worth weighing is API breakage, not tampering. cryptography is PyCA-maintained with a long stable release history; no ownership, namespace, or release-cadence anomalies.
  • Diff is 1 file (uv.lock), no new packages, no lifecycle scripts added.
  • 50.0.0 published 2026-07-31 — 10 days old, well past any cooldown window.

Recommendation

Merge now

High-severity padding-oracle fix with no back-ported alternative — 50.0.0 is the only patched version, so declining the major bump means staying vulnerable. Per the triage matrix, High urgency + Medium supply-chain risk merges now and leans on CI for functional regressions, which is the right trade here since the risk is breakage rather than compromise.

Follow-up actions

  • Watch the backend suite on the rebased run for API breaks from the 49 → 50 jump; that, not the advisory, is the thing that could bite.

Supply-chain triage per the reviewing-dependabot-prs skill. Advisories verified via gh api /advisories/; action SHA pins verified by dereferencing the annotated tag to its commit. Green CI is a functional gate, not a supply-chain signal — a malicious lifecycle script passes CI happily, so the diff was scanned for one separately.

@frankbria
frankbria enabled auto-merge (squash) August 10, 2026 03:24
@frankbria

Copy link
Copy Markdown
Owner

@dependabot rebase

@dependabot
dependabot Bot force-pushed the dependabot/uv/cryptography-50.0.0 branch from 66bb184 to 50e53b7 Compare August 10, 2026 03:25
Bumps [cryptography](https://github.com/pyca/cryptography) from 49.0.0 to 50.0.0.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@49.0.0...50.0.0)

---
updated-dependencies:
- dependency-name: cryptography
  dependency-version: 50.0.0
  dependency-type: direct:production
...

Signed-off-by: dependabot[bot] <support@github.com>
@dependabot
dependabot Bot force-pushed the dependabot/uv/cryptography-50.0.0 branch from 50e53b7 to 4f1983e Compare August 10, 2026 03:55
@frankbria
frankbria merged commit 06075ed into main Aug 10, 2026
12 of 13 checks passed
@dependabot
dependabot Bot deleted the dependabot/uv/cryptography-50.0.0 branch August 10, 2026 04:03
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant