Skip to content

Bump cryptography from 46.0.7 to 50.0.0 - #3253

Open
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/cryptography-50.0.0
Open

Bump cryptography from 46.0.7 to 50.0.0#3253
dependabot[bot] wants to merge 1 commit into
mainfrom
dependabot/uv/cryptography-50.0.0

Conversation

@dependabot

@dependabotdependabotBot commented on behalf of githubAug 5, 2026

Copy link
Copy Markdown
Contributor

Bumps cryptography from 46.0.7 to 50.0.0.

Changelog

Sourced from cryptography's changelog.

50.0.0 - 2026-07-31


* **SECURITY ISSUE**:
:func:`~cryptography.hazmat.primitives.serialization.pkcs7.pkcs7_decrypt_der`
and its PEM and S/MIME variants no longer expose distinguishable errors or
timing when unwrapping a ``RecipientInfo``'s ``encryptedKey``, which could
act as a Bleichenbacher oracle for callers that decrypt untrusted messages.
A random key is now substituted on failure, as described in :rfc:`3218`.
Credit to **@X1AOxiang** for reporting the issue. **CVE-2026-69247**
* Deprecated Diffie-Hellman key exchange over finite fields (FFDH).
Everything FFDH is deprecated, including the types in
``cryptography.hazmat.primitives.asymmetric.dh`` and loading FFDH keys or
parameters with the key loading APIs. Users should migrate to a more
modern key exchange algorithm.
* Added ``xof()`` class methods to
:class:`~cryptography.hazmat.primitives.hashes.SHAKE128` and
:class:`~cryptography.hazmat.primitives.hashes.SHAKE256` for constructing
algorithm instances configured for use with
:class:`~cryptography.hazmat.primitives.hashes.XOFHash`.
* The :mod:`X.509 verification <cryptography.x509.verification>` APIs are now
considered stable and are subject to our API stability policy.
* Added the :doc:`/cobblestone` recipe, an implementation of the
Cobblestone-128 and Cobblestone-256 instantiations of the `C2SP
chunked-encryption specification
<https://c2sp.org/chunked-encryption>`_ for streaming authenticated
encryption of large messages.
* Parsing a Signed Certificate Timestamp list now rejects encodings that
carry trailing bytes after the list or after an individual SCT, instead of
silently ignoring them.
* Added support for using :class:`~cryptography.x509.Name` as a field type in
the :doc:`/hazmat/asn1/index` module.
* Loading a public key or an EC private key now rejects DER where the
``subjectPublicKey`` (or EC ``publicKey``) ``BIT STRING`` declares a non-zero
number of unused bits, instead of silently ignoring it.
* Parsing a CRL entry's ``InvalidityDate`` extension now rejects a
``GeneralizedTime`` that carries fractional seconds or another non-DER form,
matching the strict encoding already required for every other X.509 time
field.
* :func:`~cryptography.x509.ocsp.load_der_ocsp_request` and
:func:`~cryptography.x509.ocsp.load_der_ocsp_response` now reject a request
or response whose ``version`` field is not ``v1``, the only version defined
by RFC 6960, matching the version validation already performed when loading
certificates, CSRs and CRLs.
* :class:`~cryptography.hazmat.primitives.hashes.XOFHash` is now supported
when building against AWS-LC.
* HMAC (and therefore PBKDF2-HMAC) with SHA-3 hashes is now supported when
building against AWS-LC.
* Diffie-Hellman (:doc:`/hazmat/primitives/asymmetric/dh`) is now supported
when building against AWS-LC.
</tr></table> 

... (truncated)

Commits

Dependabot compatibility score

Dependabot will resolve any conflicts with this PR as long as you don't alter it yourself. You can also trigger a rebase manually by commenting @dependabot rebase.


Dependabot commands and options

You can trigger Dependabot actions by commenting on this PR:

  • @dependabot rebase will rebase this PR
  • @dependabot recreate will recreate this PR, overwriting any edits that have been made to it
  • @dependabot show <dependency name> ignore conditions will show all of the ignore conditions of the specified dependency
  • @dependabot ignore this major version will close this PR and stop Dependabot creating any more for this major version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this minor version will close this PR and stop Dependabot creating any more for this minor version (unless you reopen the PR or upgrade to it yourself)
  • @dependabot ignore this dependency will close this PR and stop Dependabot creating any more for this dependency (unless you reopen the PR or upgrade to it yourself)
    You can disable automated security fix PRs for this repo from the Security Alerts page.

Bumps [cryptography](https://github.com/pyca/cryptography) from 46.0.7 to 50.0.0.
- [Changelog](https://github.com/pyca/cryptography/blob/main/CHANGELOG.rst)
- [Commits](pyca/cryptography@46.0.7...50.0.0)
---
updated-dependencies:
- dependency-name: cryptography
dependency-version: 50.0.0
dependency-type: indirect
...
Signed-off-by: dependabot[bot] <support@github.com>
@dependabotdependabotBot added dependencies Pull requests that update a dependency file python:uv Pull requests that update python:uv code labels Aug 5, 2026

@claudeclaudeBot left a comment

Copy link
Copy Markdown
Contributor

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

LGTM — routine Dependabot lockfile bump of cryptography 46.0.7 → 50.0.0.

What was reviewed:

  • Lockfile-only change: uv.lock hashes/wheels for cryptography, plus a benign re-resolve of the exceptiongrouptyping-extensions marker; pyproject.toml constraints are untouched, so published-package requirements are unchanged.
  • Checked SDK usage: cryptography comes in via pyjwt[crypto] and is imported directly only in src/mcp/server/request_state.py (AESGCM, HKDF, SHA256, InvalidTag) — none of these APIs are affected by the 50.0.0 breaking changes (FFDH deprecation, PKCS#7 error handling, stricter X.509/DER parsing).
  • The release also ships the CVE-2026-69247 fix (PKCS#7 Bleichenbacher oracle); the SDK doesn't call the affected pkcs7_decrypt_* APIs.
Extended reasoning...

Overview

This PR is a Dependabot-generated bump of the cryptography package from 46.0.7 to 50.0.0 in uv.lock only — the single changed file. The diff replaces the sdist/wheel URLs and hashes for cryptography and, as a side effect of re-resolution, drops the python_full_version < '3.13' marker on exceptiongroup's typing-extensions dependency (benign: typing-extensions is already locked for the project on all versions). No source code, no pyproject.toml constraints, and no CI configuration change.

Security risks

The bump is security-positive: 50.0.0 fixes CVE-2026-69247 (a Bleichenbacher oracle in pkcs7_decrypt_der and variants). The SDK does not use the affected PKCS#7 decryption APIs, nor FFDH (deprecated in this release). Direct usage is limited to src/mcp/server/request_state.py, which imports AESGCM, HKDF, SHA256, and InvalidTag — all stable primitives unaffected by the 50.0.0 changelog. Because only the lockfile changes, downstream users of the published mcp wheel are unaffected; this pins what CI and developers install. Per the repo's guidelines, the pyjwt[crypto]>=2.10.1 floor is correctly left untouched.

Level of scrutiny

Low. Lockfile-only dependency bumps are mechanical: the hashes come from PyPI via Dependabot, and correctness is validated by CI running the full test matrix (3.10–3.14 × platforms) against the new lock. With filterwarnings = ["error"] in pytest config, any new deprecation warning from cryptography 50 (e.g. FFDH) surfacing in the SDK's code paths would fail CI rather than slip through silently.

Other factors

The bug hunting system found no issues, and the PR timeline has no outstanding reviewer comments. There is no design decision or API surface change here. The main theoretical risk — a behavioral break in a four-major-version jump — is confined to dev/CI environments and gated by the existing 100%-coverage test suite.

Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

dependenciesPull requests that update a dependency filepython:uvPull requests that update python:uv code

Projects

None yet

Development

Successfully merging this pull request may close these issues.

0 participants