NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #886 most downloaded on PyPI
Implementation of JOSE Web standards
Last release 19 days ago
15 Sep 2026
Ships unpredictably
gaps range from 8 days to 2.1 years
Most releases are documented
notes for 21 of 30 stable releases
2 versions withdrawn
withdrawn after publishing
11 years old
32 releases · first in 2015
This release fixes CVE-2026-92091, a low security issue that may result in a Denial of Service on malformed JWK keys
This release fixes CVE-2026-92091, a low security issue that may result in a Denial of Service on malformed JWK keys
Full Changelog: v1.6.0...v1.6.1
Version 1.6.1 Latest
Latest
Compare
One column per quarter.
This release fixes CVE-2026-84185, a low security issue that affects only very specific and uncommon uses of the JWS interface using a JWKSet.
This release fixes CVE-2026-84185, a low security issue that affects only very specific and uncommon uses of the JWS interface using a JWKSet.
Full Changelog: v1.5.9...v1.6.0
Add ML-DSA post-quantum signature support (RFC 9964) by @rjeffman in #384
CVE-2026-80179
Full Changelog: v1.5.8...v1.5.9
Fix list iteration in claim format validation by @simo5 in #375
Full Changelog: v1.5.7...v1.5.8
Full Changelog: https://github.com/latchset/jwcrypto/compare/v1.5.7...v1.5.8
JWE: allow general (non flattened) serialization syntax by @Thomas-Mollard in #351
Full Changelog: v1.5.6...v1.5.7
Full Changelog: https://github.com/latchset/jwcrypto/compare/v1.5.6...v1.5.7
Address potential DoS with high compression ratio by @simo5 in #349
Full Changelog: v1.5.5...v1.5.6
Full Changelog: https://github.com/latchset/jwcrypto/compare/v1.5.5...v1.5.6
Version 1.5.6 - Moderate Security release
Compare
This version fixes a pypi distribution problem introduced in 1.0 when pushing was automated. With 1.5.5 a binary wheel is now also made available on p
This version fixes a pypi distribution problem introduced in 1.0 when pushing was automated. With 1.5.5 a binary wheel is now also made available on pypi.
Full Changelog: https://github.com/latchset/jwcrypto/compare/v1.5.4...v1.5.5
This version fixes a pypi distribution problem introduced in 1.0 when pushing was automated.
With 1.5.5 a binary wheel is now also made available on pypi.
Full Changelog: v1.5.4...v1.5.5
One more release bump to address issues with typing_extensions minimum required version
One more release bump to address issues with typing_extensions minimum required version
Full Changelog: v1.5.3...v1.5.4
Bumping release due to inconsistency in python 3.6 support that affected pypi jwcrypto-1.5.3.tar.gz.sha512sum.txt jwcrypto-1.5.3.tar.gz
Bumping release due to inconsistency in python 3.6 support that affected pypi
jwcrypto-1.5.3.tar.gz.sha512sum.txt
jwcrypto-1.5.3.tar.gz
Full Changelog: v1.5.2...v1.5.3
replace deprecated package with typing_extensions by @david-homelend in #337
This is a minor maintenance release to improve interoperability with debuggers
Note: yanked from pypi due to 3.6 incompatibility, use 1.5.3
Full Changelog: v1.5.1...v1.5.2
This is a minor security release to fix a potential DoS for applications that allow the use of symmetric keys with pbkdf2.
This is a minor security release to fix a potential DoS for applications that allow the use of symmetric keys with pbkdf2.
Full Changelog: v1.5.0...v1.5.1
This is a minor security release to fix a potential DoS for applications that allow the use of symmetric keys with pbkdf2.
Full Changelog: https://github.com/latchset/jwcrypto/compare/v1.5.0...v1.5.1
Minor bugfixes and the addition of Brainpool curves. As mentioned in the commit: "The use of these algorithms is specified solely by the gematik GmbH
Version 1.5
Minor bugfixes and the addition of Brainpool curves.
As mentioned in the commit: "The use of these algorithms is specified solely by the gematik GmbH – National Digital Health Agency - for use in german e-health applications"
This version also raises the minimum Cryptography version required to 3.4 and the minimum python version tested to 3.7
Full Changelog: v1.4.2...v1.5.0
Another minor release to fix a mistake in the compatibility heuristics which affects actual applications
Another minor release to fix a mistake in the compatibility heuristics which affects actual applications
Full Changelog: https://github.com/latchset/jwcrypto/compare/v1.4.1...v1.4.2
Another minor release to fix a mistake in the compatibility heuristics which affects actual applications
Full Changelog: v1.4.1...v1.4.2
This is a minor release focused on improving backwards compatibility with applications after the API breaking changes introduced in 1.4 This patch add…
This is a minor release focused on improving backwards compatibility with applications after the API breaking changes introduced in 1.4 This patch adds a bunch of heuristics to be able to safely autodetect a token type. It has been tested to solve the compatibility issues (ie old code works without modifications and fully securely) with at least one large application.
Full Changelog: https://github.com/latchset/jwcrypto/compare/v1.4.0...v1.4.1
Nothing published for this version
Handle a regression when the JWTMissing Key exception was removed when a key is not found in a JWKSet. This adds a new generic JWKeyNotFound exception
Handle a regression when the JWTMissing Key exception was removed when a key is not found in a JWKSet. This adds a new generic JWKeyNotFound exception now returned by JWS and JWE when a JWKSet is used and JWTMissingKey now subclasses this new exception. This way code can now simply trap JWkeyNotFound, while older code can still use JWTMissingKey. Also fix documentation generation.
Full Changelog: https://github.com/latchset/jwcrypto/compare/v1.3.0...v1.3.1
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fixes a couple of serious regressions spotted in 0.9
Fixes a couple of serious regressions spotted in 0.9
Changelog:
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Fix bytes/str comparison in JWE
compatibility with cryptography 2.0
Fixed nbf incorrect validation #71
A regression was introduced in 0.3.0 that caused issues in FreeIPA and Custodia projects. Also docs version and tox/travis configurations were improve
A regression was introduced in 0.3.0 that caused issues in FreeIPA and Custodia projects. Also docs version and tox/travis configurations were improved to test Python 3.4 and 3.5 Python 3.3 is not officially supported anymore
Some interfaces have also been deprecated, and marked as such in the documentation, they may be removed in a future release.
This version completes the support for all algorithms specified by the JOSE RFCs, as well as adds better interfaces to deal with JWKs and implements the JWK Thumbprint standard too.
Some interfaces have also been deprecated, and marked as such in the documentation, they may be removed in a future release.
Fixed a few issues with symmetric and EC keys generation. Added more tests and Travis CI integration.
Fixed a few issues with symmetric and EC keys generation. Added more tests and Travis CI integration.
Now that the JOSE working group has produced official RFC it is time for a new release that updates all references and fixes a few bugs recently disco
Now that the JOSE working group has produced official RFC it is time for a new release that updates all references and fixes a few bugs recently discovered while using the library
Your coding agent can read these notes before it upgrades. Set up the MCP server →