NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #328 most downloaded on PyPI
CBOR (de)serializer with extensive tag support
Last release 3 days ago
01 Oct 2026
Release timing varies
gaps range from 2 weeks to 10 months
Nearly every release is documented
notes for 46 of 48 stable releases
1 version withdrawn
withdrawn after publishing
10 years old
50 releases · first in 2016
Fixed CBORSimpleValue hashing inconsistently with the integer it compares equal to ( #334 ; PR by @sahvx655-wq )
CBORSimpleValue hashing inconsistently with the integer it compares equal to (#334; PR by @sahvx655-wq)dict or CBORTag instead of the value returned by object_hook or tag_hook, a regression from 5.x (#343; PR by @sahvx655-wq)PanicException when trying to decode an epoch-form date (tag 100) with a payload near i32::MAX which then overflowed the addition instead of raising a clean decode error (#340; PR by @sahvx655-wq)~datetime.datetime instead of rejecting it (#347; PR by @sahvx655-wq)CBOREncoder no longer flushing its output or resetting its shared container and string reference tracking after an encode() call had raised an exception (#348; PR by @sahvx655-wq)One column per quarter.
Fixed frozendict deriving its hash from its keys and its values as two independent sets, so that frozendicts holding the same keys and the same values
frozendict deriving its hash from its keys and its values as two independent sets, so that frozendicts holding the same keys and the same values all collided regardless of how the two were paired; since the decoder builds a frozendict for every map in an immutable position, a payload keyed by such maps decoded in quadratic time (#333; PR by @sahvx655-wq)bytearray values in the string reference namespace, unlike bytes and str; since the decoder registers every byte string it reads, a single bytearray desynchronised the namespace and made subsequent string references resolve to the wrong value (#332; PR by @sahvx655-wq)int.from_bytes() also accepts an array (or a map, whose keys it iterates), so a tag wrapping one of those was coerced into an integer instead of being rejected as malformed (#326; PR by @sahvx655-wq)Fixed the decoder registering 6-byte strings in the string reference namespace at indices 65536–4294967295 where the encoder does not, desynchronising
+ instead of building the result once (#316; PR by @sahvx655-wq)datetime_as_timestamp encoding whole-second datetimes before 1970 or after 2106 as floats instead of integers, because the timestamp was narrowed through an unsigned 32-bit integer (#317; PR by @sahvx655-wq)CBORDecodeError reading invalid types in input array; the encoder emits them as [address, null, zone id] but the decoder only handled the network and interface array forms, so a scoped ~ipaddress.IPv6Address could not be decoded back (#324; PR by @sahvx655-wq)Fixed incorrect tracking of string references for definite-length text strings of length greater than 65536 ( #308 ; PR by @sahvx655-wq )
cbor2.load() crash caused by incorrect handling of internal read buffer extension during stream deserialization. (#307; PR by @Noderyos)Fixed cbor2.load() returning corrupted data for payloads exceeding 4096 bytes
cbor2.load() returning corrupted data for payloads exceeding 4096 bytes (#304)Added the allow_duplicate_keys parameter to CBORDecoder , load and loads (default: True ). When set to False , a CBORDecodeError is raised upon encoun
allow_duplicate_keys parameter to CBORDecoder, load and loads (default: True). When set to False, a CBORDecodeError is raised upon encountering a duplicate key within the same map. (#283)memoryview or bytearray) in addition to bytes (#297)Fixed an error in the mutability logic during decoding, leading to values being decoded as immutable in unexpected places
No changes since v6.0.0rc1
BACKWARD INCOMPATIBLE Changed the signature of the tag_hook decoder callables to accept ( CBORTag , immutable as arguments instead of CBORDecoder , CB…
MAJOR REWRITE: The Python and C implementations of the encoder and decoder were replaced with a single, Rust-based implementation in the interest of maintainability.
Here are some of the highlights:
CBORDecodeErrorBACKWARD INCOMPATIBLE Changed the signature of the tag_hook decoder callables to accept (CBORTag, immutable as arguments instead of CBORDecoder, CBORTag)
BACKWARD INCOMPATIBLE Changed the signature of the object_hook decoder callables to accept (Mapping[Any, Any], bool) instead of (CBORDecoder, dict[Any, Any])
BACKWARD INCOMPATIBLE Removed the break_marker singleton as no longer necessary
BACKWARD INCOMPATIBLE Removed the CBORDecodeValueError exception, instead chaining ValueError or TypeError to a CBORDecodeError
BACKWARD INCOMPATIBLE Changed the decoding of semantic tag 261 to yield an IPv4Interface or IPv6Interface if the address contains host bits
BACKWARD INCOMPATIBLE Removed the individual decoding functions from the API as they were mistakenly called directly by users. Please open an issue if you need them back.
BACKWARD INCOMPATIBLE Changed the encoding of IP addresses to use the semantic tags 52 and 54 instead of the deprecated 260 and 261 (#232)
BACKWARD INCOMPATIBLE Dropped the deprecated cbor2.decoder and cbor2.encoder modules – everything in the API is now importable directly from cbor2
BACKWARD INCOMPATIBLE The cbor2.FrozenDict class has now been renamed frozendict and is not available on Python 3.15 where the built-in frozendict class must be used instead
Added the semantic_decoders decoder option to add or override decoders for specific semantic tags
Added the immutable decoder flag to always use immutable containers where possible when decoding a CBOR stream
Added the allow_indefinite decoder option to optionally disallow indefinite-length strings and containers
Dropped support for Python 3.9
Fixed the decoder not rejecting invalid two-byte simple value sequences (0xF800 - 0xF81F)
Added the max_depth decoder parameter to limit the maximum allowed nesting level of containers, with a default value of 400 levels ( CVE-2026-26209 )
max_depth decoder parameter to limit the maximum allowed nesting level of containers, with a default value of 400 levels (CVE-2026-26209)read_size from 4096 to 1 for backwards compatibility. The buffered reads introduced in 5.8.0 could cause issues when code needs to access the stream position after decoding. Users can opt-in to faster decoding by passing read_size=4096 when they don't need to access the stream directly after decoding. Added a direct read path for read_size=1 to avoid buffer management overhead. (#275; PR by @andreer)CBOREncoder.encode_shared() (#287)str_errors setting when decoding strings, and improved string decoding performance by using stack allocation for small strings and eliminating unnecessary conditionals. Benchmarks show 9-17% faster deserialization. (#255; PR by @andreer)Added readahead buffering to C decoder for improved performance. The decoder now uses a 4 KB buffer by default to reduce the number of read calls. Ben
Fixed a read(-1) vulnerability caused by boundary handling error (#264 \< \>\_; PR by @tylzh97)
Added support for Python 3.14 (no free-threading support yet, sorry)
Published binary wheels for Python 3.13
Fixed compilation of C extension failing on GCC 14
Fixed decoding of epoch-based dates being affected by the local time zone in the C extension
Fixed __hash__() of the C version of the CBORTag type crashing when there's a recursive reference cycle
__hash__() of the C version of the CBORTag type crashing when there's a recursive reference cyclecbor2.dump(), cbor2.load(), CBOREncoder and CBORDecoder to be IO[bytes] instead of BytesIOSystemError to be raised, or even a buffer overflow to occur when decoding a long text string that contained only ASCII characterscbor2.load() and cbor2.load() to return Any instead of object so as not to force users to make type castsFixed use-after-free in the decoder's C version when prematurely encountering the end of stream
CBORDecodeEOF when decoding a text string longer than 65536 bytesAdded the cbor2 command line tool (for pipx run cbor2)
cbor2 command line tool (for pipx run cbor2)CBOR2_BUILD_C_EXTENSION is set to 1.SystemError in the C extension when decoding a Fractional with a bad number of arguments or a non-tuple valueSystemError in the C extension when the decoder object hook raises an exceptionMemoryError when maliciously constructed bytestrings or string (declared to be absurdly large) are being decodedUnicodeDecodeError from failed parsing of a UTF-8 text string not being wrapped as CBORDecodeValueErrorTypeError or ZeroDivisionError from a failed decoding of Fraction not being wrapped as CBORDecodeValueErrorTypeError or ValueError from a failed decoding of UUID not being wrapped as CBORDecodeValueErrorTypeError from a failed decoding of MIMEMessage not being wrapped as CBORDecodeValueErrorOverflowError, OSError or ValueError from a failed decoding of epoch-based datetime not being wrapped as CBORDecodeValueErrorFixed CBORSimpleValue allowing the use of reserved values (24 to 31) which resulted in invalid byte sequences
CBORSimpleValue allowing the use of reserved values (24 to 31) which resulted in invalid byte sequencesThe cbor2.encoder, cbor2.decoder or cbor2.types modules were deprecated – import their contents directly from cbor2 from now on. The old modules will…
cbor2.encoder, cbor2.decoder or cbor2.types modules were deprecated – import their contents directly from cbor2 from now on. The old modules will be removed in the next major release.fp attribute of the built-in version of CBORDecoder and CBOREncoder where the getter returns an invalid pointer if the read method of the file was a built-in method- Fix MemoryError when decoding Tags on 32bit architecture. (Sekenre)
Fix MemoryError when decoding Tags on 32bit architecture. (Sekenre)
- Added official Python 3.11 support (agronholm)
Added official Python 3.11 support (agronholm)
Raise proper exception on invalid bignums (Øyvind Rønningstad)
Make Tagged item usable as a map key (Niels Mündler)
Eliminate potential memory leak in tag handling (Niels Mündler)
Documentation tweaks (Adam Johnson)
REMOVED Due to potential memory leak bug
REMOVED Due to potential memory leak bug
- Removed support for Python < 3.7
Removed support for Python < 3.7
Various build system improvements for binary wheels (agronholm)
Migrated project to use pyproject.toml and pre-commit hooks (agronholm)
Nothing published for this version
- Fix segfault when initializing CBORTag with incorrect arguments (Sekenre)
Fix segfault when initializing CBORTag with incorrect arguments (Sekenre)
Fix sphinx build warnings (Sekenre)
- Fix SystemErrors when using C-backend, meaningful exceptions now raised (Sekenre)
Fix SystemErrors when using C-backend, meaningful exceptions now raised (Sekenre)
Fix precision loss when decoding base10 decimal fractions (Sekenre)
Made CBORTag handling consistent between python and C-module (Sekenre)
Added new feature stringrefs, which makes repetitive dictionary structures more compact. Use with care since support for this is rare in other CBOR im
Added new feature stringrefs, which makes repetitive dictionary structures more compact. Use with care since support for this is rare in other CBOR implementations.
This release includes some bugfixes around decoding invalid data, which may improve security on decoding untrusted data.
Fix various bounds checks in the C-backend (Sekenre)
More testing of invalid/corrupted data (Sekenre)
Support for String References (xurtis)
Update Docs to refer to new RFC8949
- Removed support for Python < 3.6
Removed support for Python < 3.6
Nothing published for this version
Last release in the 5.x series as we will be removing support for Python 2.7 to 3.5
Last release in the 5.x series as we will be removing support for Python 2.7 to 3.5
Final version tested with Python 2.7 and 3.5
README: Announce deprecation of Python 2.7, 3.5
README: More detail and examples
Bugfix: Fix segfault on loading huge arrays with C-backend (Sekenre)
Build system: Allow packagers to force C-backend building or disable using env var (jameshilliard)
Feature: cbor2.tool Command line diagnostic tool (Sekenre)
Feature: Ignore semantic tag used for file magic 55799 AKA “Self-Described CBOR” (kalcutter)
- Bugfix: Refcount bug in C lib causing intermittent segfaults on shutdown (tdryer)
Bugfix: Refcount bug in C lib causing intermittent segfaults on shutdown (tdryer)
- Build system: Making C lib optional if it fails to compile (chiefnoah)
Build system: Making C lib optional if it fails to compile (chiefnoah)
Build system: Better Glibc version detection (Sekenre and JayH5)
Tests: Positive and negative bignums (kalcutter)
Bugfix: Fractional seconds parsing in datetimes (kalcutter)
- Minor API change: CBORSimpleValue is now a subclass of namedtuple and allows all numeric comparisons. This brings functional parity between C and Py
Minor API change: CBORSimpleValue is now a subclass of namedtuple and allows all numeric comparisons. This brings functional parity between C and Python modules.
Fixes for C-module on big-endian systems including floating point decoding, smallint encoding, and boolean argument handling. Tested on s390x and MIPS32.
Increase version requred of setuptools during install due to unicode errors.
- Fix deprecation warning on python 3.7, 3.8 (mariano54)
Fix deprecation warning on python 3.7, 3.8 (mariano54)
Minor documentation tweaks
- BACKWARD INCOMPATIBLE CBOR does not have a bare DATE type, encoding dates as datetimes is disabled by default (PR by Changaco)
BACKWARD INCOMPATIBLE CBOR does not have a bare DATE type, encoding dates as datetimes is disabled by default (PR by Changaco)
BACKWARD INCOMPATIBLE CBORDecoder.set_shareable() only takes the instance to share, not the shareable’s index
BACKWARD INCOMPATIBLE CBORError now descends from Exception rather than ValueError ; however, subordinate exceptions now descend from ValueError (where appropriate) so most users should notice no difference
BACKWARD INCOMPATIBLE CBORDecoder can now raise CBORDecodeEOF which inherits from EOFError supporting streaming applications
Optional Pure C implementation by waveform80 that functions identically to the pure Python implementation with further contributions from: toravir, jonashoechst, Changaco
Drop Python 3.3 and 3.4 support from the build process; they should still work if built from source but are no longer officially supported
Added support for encoding and decoding ipaddress.IPv4Address , ipaddress.IPv6Address , ipaddress.IPv4Network , and ipaddress.IPv6Network (semantic tags 260 and 261)
- Fixed bigint encoding taking quadratic time
Fixed bigint encoding taking quadratic time
Fixed overflow errors when encoding floating point numbers in canonical mode
Improved decoder performance for dictionaries
Minor documentation tweaks
- Fixed encoding of negative decimal.Decimal instances (PR by Sekenre)
Fixed encoding of negative decimal.Decimal instances (PR by Sekenre)
- Added canonical encoding (via canonical=True ) (PR by Sekenre)
Added canonical encoding (via canonical=True ) (PR by Sekenre)
Added support for encoding/decoding sets (semantic tag 258) (PR by Sekenre)
Added support for encoding FrozenDict (hashable dict) as map keys or set elements (PR by Sekenre)
- Fixed silent truncation of decoded data if there are not enough bytes in the stream for an exact read ( CBORDecodeError is now raised instead)
Fixed silent truncation of decoded data if there are not enough bytes in the stream for an exact read ( CBORDecodeError is now raised instead)
- BACKWARD INCOMPATIBLE Value sharing has been disabled by default, for better compatibility with other implementations and better performance (since…
BACKWARD INCOMPATIBLE Value sharing has been disabled by default, for better compatibility with other implementations and better performance (since it is rarely needed)
BACKWARD INCOMPATIBLE Replaced the semantic_decoders decoder option with the CBORDecoder.tag_hook option
BACKWARD INCOMPATIBLE Replaced the encoders encoder option with the CBOREncoder.default option
BACKWARD INCOMPATIBLE Factored out the file object argument ( fp ) from all callbacks
BACKWARD INCOMPATIBLE The encoder no longer supports every imaginable type implementing the Sequence or Map interface, as they turned out to be too broad
Added the CBORDecoder.object_hook option for decoding dicts into complex objects (intended for situations where JSON compatibility is required and semantic tags cannot be used)
Added encoding and decoding of simple values ( CBORSimpleValue ) (contributed by Jerry Lundström)
Replaced the decoder for bignums with a simpler and faster version (contributed by orent)
Made all relevant classes and functions available directly in the cbor2 namespace
Added proper documentation
- Fixed TypeError when trying to encode extension types (regression introduced in 3.0.3)
Fixed TypeError when trying to encode extension types (regression introduced in 3.0.3)
- No changes, just re-releasing due to git tagging screw-up
No changes, just re-releasing due to git tagging screw-up
- Fixed decoding failure for datetimes with microseconds (tag 0)
Fixed decoding failure for datetimes with microseconds (tag 0)
- Fixed error in the cyclic structure detection code that could mistake one container for another, sometimes causing a bogus error about cyclic data s
Fixed error in the cyclic structure detection code that could mistake one container for another, sometimes causing a bogus error about cyclic data structures where there was none
- BACKWARD INCOMPATIBLE Encoder callbacks now receive three arguments: the encoder instance, the value to encode and a file-like object. The callback…
BACKWARD INCOMPATIBLE Encoder callbacks now receive three arguments: the encoder instance, the value to encode and a file-like object. The callback must must now either write directly to the file-like object or call another encoder callback instead of returning an iterable.
BACKWARD INCOMPATIBLE Semantic decoder callbacks now receive four arguments: the decoder instance, the primitive value, a file-like object and the shareable index for the decoded value. Decoders that support value sharing must now set the raw value at the given index in decoder.shareables .
BACKWARD INCOMPATIBLE Removed support for iterative encoding ( CBOREncoder.encode() is no longer a generator function and always returns None )
Significantly improved performance (encoder ~30 % faster, decoder ~60 % faster)
Fixed serialization round-trip for undefined (simple type 23)
Added proper support for value sharing in callbacks
- BACKWARD INCOMPATIBLE Deserialize unknown tags as CBORTag objects so as not to lose information
BACKWARD INCOMPATIBLE Deserialize unknown tags as CBORTag objects so as not to lose information
Fixed error messages coming from nested structures
- Fixed deserialization of cyclic structures
Fixed deserialization of cyclic structures
- Initial release
Initial release
Your coding agent can read these notes before it upgrades. Set up the MCP server →