NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #484 most downloaded on PyPI
ECDSA cryptographic signature library (pure python)
Last release 6 months ago
26 Mar 2026
Release timing varies
gaps range from 4 weeks to 1.8 years
Most releases are documented
notes for 15 of 21 stable releases
Nothing withdrawn
no release was ever pulled
16 years old
23 releases · first in 2010
Fix CVE-2026-33936, a DER parsing issue in remove_octet_string(), remove_constructed(), and remove_implitic() where a truncated buffer wasn't detected…
Bug fixes:
remove_octet_string(),
remove_constructed(), and remove_implitic() where a truncated buffer
wasn't detected. This can lead to high level functions, like
SigningKey.from_der() to raise unexpected exceptions.
(Mohamed Abdelaal (0xmrma))Maintenance:
der.remove_implicit and der.encode_implicit for decoding and encoding DER IMPLICIT values with custom tag values and arbitrary classes
New API:
der.remove_implicit and der.encode_implicit for decoding and
encoding DER IMPLICIT values with custom tag values and arbitrary
classesBug fixes:
s is just slightly
above half of curve orderMaintenance:
six.b literals (Alexandre Detiste)One column per quarter.
int_to_string, string_to_int, and digest_integer from ecdsa.ecdsa module are now considered deprecated, they will be removed in a future release
to_ssh in VerifyingKey and SigningKey, supports Ed25519 keys only
(Pablo Mazzini)_rwlock module as it's unusedsix.b literals (Alexandre Detiste)int_to_string, string_to_int, and digest_integer from ecdsa.ecdsa
module are now considered deprecated, they will be removed in a future
releaseBetter handling of malformed curve parameters (as in CVE-2022-0778); make python-ecdsa raise MalformedPointError instead of AssertionError.
curve_by_name in curves module to get a Curve object by providing curve
name.VerifyingKey encoded with explicit parameters use the same
kind of point encoding for public key and curve generator.MalformedPointError instead of AssertionError.explicit vs named_curve confusion in VerifyingKey docs.changes since 0.18.0-beta1
Support for point precomputation for EdDSA.
changes since 0.18.0-beta1
Support for EdDSA (Ed25519, Ed448) signature creation and verification.
Keys that use explicit curve parameters can now be read and written. Reading of explicit curves can be disabled by using the valid_curve_encodings key
valid_curve_encodings keyword argument in VerifyingKey.from_pem(),
VerifyingKey.from_der(), SigningKey.from_pem(), and
SigningKey.from_der().curve_parameters_encoding keyword argument of VerifyingKey.to_pem(),
VerifyingKey.to_der(), SigningKey.to_pem(), or SigningKey.to_der() to
specify the format. By default named_curve will be used, unless the
curve doesn't have an associated OID (as will be the case for an unsupported
curve), then explicit encoding will be used.valid_encodings keyword argument in
ECDH.load_received_public_key_bytes(), VerifyingKey.from_string(),
VerifyingKey.from_pem(), VerifyingKey.from_der().PointJacobi and Point now inherit from AbstractPoint that implements
the methods for parsing points. That added from_bytes() and
to_bytes() methods to both of them.Curve class supports new to_der(), from_der(), to_pem(), and
from_pem() methods.RSZeroError, and that
SigningKey.sign_deterministic() won't raise it.== and != for Public_key, Private_key, Point,
PointJacobi, VerifyingKey, and SigningKey so that it behaves
consistently and in the expected way both in Python 2 and Python 3.PointJacobi for keeping shared state
so that when calculation is aborted with KeyboardInterrupt, the state doesn't
become corrupted (this fixes the occasional breakage of ecdsa in interactive
shells).speed.py script now provides performance for signature verification
without use of precomputation.VerifyingKey.precompute() supports lazy argument to delay precomputation to the first time the key is used to verify a signature.
VerifyingKey.precompute() supports lazy argument to delay precomputation
to the first time the key is used to verify a signature.VerifyingKey.precompute() method.VerifyingKey.precompute() method.Support for reading and writing private keys in PKCS#8 format.
to_pem and to_der now accept new parameter, format, to specify
the format of the encoded files, either the dafault, legacy "ssleay", or
the new pkcs8 to use PKCS#8. Note that only unencrypted PKCS#8 files are
supported.allow_truncate to verify in VerifyingKey, it defaults to True,
when specified as False, use of large hashes smaller than curves will be
disallowed (as it was in 0.14.1 and earlier).PointJacobi and thus SigningKey and VerifyingKey pickleable.to_pem functions return bytes not str, document them as such.from_pem and from_pem in SigningKey returns SigningKey, document them
as such.assert_ in test suite.from curves import * will now correctly import BRAINPOOLP256r1 and BRAINPOOLP320r1 curves.
from curves import * will now correctly import BRAINPOOLP256r1 and
BRAINPOOLP320r1 curves.VerifyingKey now supports the precompute() method to further speed up
signature verification with the given instance of the key.VerifyingKey, SigningKey, Public_key, Private_key and
CurveFp now have __eq__ methods.ecdsa.ecdh module and ECDH class.PointJacobi added.VerifyingKey.verify_digest, SigningKey.sign_digest and
SigningKey.sign_digest_deterministic methods now accept allow_truncate
argument to enable use of hashes larger than the curve order.VerifyingKey from_pem and from_der now accept hashfunc parameter
like other from* methods.VerifyingKey has precompute method now.VerifyingKey.from_public_point may now not perform validation of public
point when validate_point=False argument is passed to method.CurveFp constructor now accepts the h parameter - the cofactor of the
elliptic curve, it's used for selection of algorithm of public point
verification.randrange now will now perform much fewer calls to system random number
generator.PointJacobi introduced and used as the underlying implementation; speeds up
the library by a factor of about 20.gmpy and gmpy2. When they are
available, the elliptic curve calculations will be about 3 times faster.six module (1.9.0) is now specified explicitly
in setup.py and tested against.Remove the obsolete six.py file from wheel distribution file on pypi
Remove the obsolete six.py file from wheel distribution file on pypi
Multiple functions in numbertheory are considered deprecated: phi, carmichael, carmichael_of_factorized, carmichael_of_ppower, order_mod, largest_fact…
UnexpectedDER exception on malformed DER
encoded byte strings.BadSignatureError.SigningKey and VerifyingKey methods that should accept
bytes-like objects actually do accept them (also avoid copying input strings).SigningKey.sign_digest_deterministic use default object hashfunc when
none was provided.encode_integer now works for large integers.encode_oid and remove_object correctly handle OBJECT IDENTIFIERs
with large second subidentifier and padding in encoded subidentifiers.extra_entropy parameter to further
randomise the selection of k (the nonce) for signature, as specified in
RFC6979.CurveFp: __str__ is now supported.SigningKey.sign_deterministic, SigningKey.sign_digest_deterministic and
generate_k: extra_entropy parameter was addedSignature.recover_public_keys was addedVerifyingKey.from_public_key_recovery andVerifyingKey.from_public_key_recovery_with_digest were addedVerifyingKey.to_string: encoding parameter was addedVerifyingKey.to_der and SigningKey.to_der: point_encoding parameter was
added.encode_bitstring: unused parameter was addedremove_bitstring: expect_unused parameter was addedSECP256k1 is now part of curves * importCurves: __repr__ is now supportedVerifyingKey: __repr__ is now supportedfrom ecdsa.keys import * will now import only objects defined in that module.VerifyingKey.from_string
will rise now the MalformedPointError exception (that inherits from
AssertionError but is not it).numbertheory are considered deprecated: phi,
carmichael, carmichael_of_factorized, carmichael_of_ppower,
order_mod, largest_factor_relatively_prime, kinda_order_mod. They will
now emit DeprecationWarning when used. Run the application or test suite
with -Wd option or with PYTHONWARNINGS=default environment variable to
verify if those methods are not used. They will be removed completely in a
future release.encode_bitstring and decode_bitstring expect the number of unused
bits to be passed as an argument now. They will emit DeprecationWarning
if they are used in the deprecated way.modular_exp: will emit DeprecationWarningk value (the nonce).inverse_mod function, increasing performance by about
40% for all operations.sixsrc subdirectorytox -e speed, or
after installation, with python speed.py)der module.VerifyingKey, SigningKey and signature encoder/decoder
functions added.math.gcd, when provided.Fix CVE-2019-14853 - possible DoS caused by malformed signature decoding Fix CVE-2019-14859 - signature malleability caused by insufficient checks of…
Fix CVE-2019-14853 - possible DoS caused by malformed signature decoding Fix CVE-2019-14859 - signature malleability caused by insufficient checks of DER encoding
Also harden key decoding from string and DER encodings.
Restore compatibility of setup.py with Python 2.6 and 2.7.
Restore compatibility of setup.py with Python 2.6 and 2.7.
Fix the PyPI wheel - the old version included .pyc files.
Fix the PyPI wheel - the old version included .pyc files.
Fix the argument order for Curve constructor (put openssl_name= at the end, with a default value) to unbreak compatibility with external callers who u
Fix the argument order for Curve constructor (put openssl_name= at the end,
with a default value) to unbreak compatibility with external callers who used
the 0.11 convention.
Switch to Versioneer for version-string management (fixing the broken ecdsa.__version__ attribute). Add Curve.openssl_name property. Mention secp256k1
Switch to Versioneer for version-string management (fixing the broken
ecdsa.__version__ attribute). Add Curve.openssl_name property. Mention
secp256k1 in README, test against OpenSSL. Produce "wheel" distributions. Add
py3.4 and pypy3 compatibility testing. Other minor fixes.
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Your coding agent can read these notes before it upgrades. Set up the MCP server →