NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
PyPI · #2911 most downloaded on PyPI
A lightweight and fast implementation of QUIC and HTTP/3
Last release 3 days ago
01 Oct 2026
Ships fairly regularly
a new release about every 5 weeks
Nearly every release is documented
notes for 56 of 56 stable releases
3 versions withdrawn
withdrawn after publishing
3 years old
59 releases · first in 2023
One column per quarter.
Updated aws-lc-rs v1.18.0 to v1.18.1
Changed
Misc
nextUpdate field now raiseValueError instead of panicking. (private)Rare HTTP/3 hang caused by losing QUIC stream reservations before application keys became available.
Fixed
Address a very subtle and rare race condition in the QuicConnectionCore on initialization.
Fixed
Added QuicConnection.should_wait_for_ack(now) as the supported replacement for inspecting private loss-recovery state when coordinating flow control m
Fixed
QuicConnection.should_wait_for_ack(now) as the supported replacementQuicConnection such as get_peercert.Rebuilt QuicConnection around a single authoritative Rust transport core. The pure-Python packet-processing path had reached a practical performance c
Changed
QuicConnection around a single authoritative Rust transport core.aioquic and subsequently developed in qh3. The public PythonQuicConnection internals are no longer compatible with the formerCongestion and loss algorithms against more brittle network connections
Fixed
Changed
Updated aws-lc-rs v1.17.0 to v1.17.1
Changed
Added guard against too large msg (during PING frame probe) datagram in non-GSO/quinn-udp path.
Fixed
Handshake failure ( got type 20, wanted type 8 ) against servers that accept the TLS application_settings (ALPS) offer.
Fixed
got type 20, wanted type 8) against servers that accept theapplication_settings (ALPS) offer.Total refresh of default QUIC and HTTP3 parameters to better blend in with mainstream browser traffic.
Changed
signature_algorithms by default.supported_versions now defaults to QUIC v1 only. v2 become opt-in.status_request (OCSP) extension is no longer offered.active_connection_id_limit is no longer advertised by default.Added
brotli (CPython) or brotlicffi (PyPy) package is installed.QuicConfiguration to opt back into the former behaviors: signature_algorithms,offer_ec_key_shares, offer_certificate_status_request and active_connection_id_limit.Fixed
assert statement in favor of unavoidable hard checks and raises.StreamWriter.Remediation on various QUIC compliance items (enabled by 3rd party audit).
Fixed
Aggressive optimizations in the library. Expect up to 30% improvement in general. We are aware that qh3 have a significant part of the logic in pure P
Changed
Fixed
Added
Unexpected crash when a corrupted datagram is fed into the QUIC state machine.
Fixed
Changed
Performance issue on first TLS handshake due to an unnecessary CA store self signature check.
Fixed
HTTP/3 SETTINGS_H3_DATAGRAM identifier now uses the RFC 9297 value 0x33 instead of the obsolete draft ietf masque value 0xFFD277. This fixes interop w
Fixed
SETTINGS_H3_DATAGRAM identifier now uses the RFC 9297 value 0x33
instead of the obsolete draft ietf masque value 0xFFD277.
This fixes interop with RFC 9297-compliant peers. The legacy identifier is still
accepted on receive for backward compatibility. (https://github.com/jawah/qh3/issues/107)Changed
ls-qpack-rs strict enforcement struct assert at build time.
Fixed
Changed
Misc
Encrypted Hello (ECH) support based on RFC 9849 specifications. We do not support ECH for the server-side. Only intended for client-side usage.
Added
Changed
Fixed
Security
Misc
Client side MTU discovery to probe for max datagram size.
Added
Changed
backport (https://github.com/aiortc/aioquic/pull/604) avoid assertion error when receiving multiple STOP_SENDING.
Fixed
Changed
Misc
Explicit support for Python 3.14
Changed
Added
Misc
OCSP and CRL related helpers improved. This is not useful for end users of qh3.
Changed
Misc
The caextra recently added in the Configuration is reverted. After much consideration this was a mistake. End-users are already pushing either willing
Removed
caextra recently added in the Configuration is reverted. After much consideration this was a mistake.
End-users are already pushing either willingly or by accident intermediate CA or even non TLS client auth or server
auth certificate in the regular CA bundle. We had to find another way.Changed
Fixed
Misc
Passing extra intermediates CA in the configuration so that we could discretely rebuild the chain before validation. This is most useful in a corporat
Added
caextra property.Fixed
Changed
Misc
Parsing of SEC1/PKCS8 EC Private Key. https://github.com/jawah/qh3/issues/73
Fixed
Fixed - Parsing of SEC1/PKCS8 ECC Private Key. https://github.com/jawah/qh3/issues/73
General performance improvements in various parts of the code. Up to 5% faster (against 1.4.5).
Misc
Changed
Added
General performance improvements in various parts of the code. Up to 15% faster (against 1.4.4).
Misc
Fixed
Removed
qh3.buffer as well as qh3._crypto. Those were not supposed to be used externally anyway.General performance improvements in various parts of the code. Up to 25% faster.
Misc
ls-qpack updated to v2.6.1 with a fix for big endian architectures (e.g. s390x).
Changed
Upgraded aws-lc-rs from 1.12.2 to 1.12.5
Changed
Misc
Fixed
Bad IDNA label raise inappropriate exception.
Fixed
Support for IDNA domain name using UTS 46 for both server and client
Added
Changed
x86 (32-bits) wheels are now automatically published to PyPI for both Linux (i686) and Windows (win32).
Changed
Misc
Updated pyo3 from 0.23.3 to 0.23.4
Changed
Post-Quantum key-exchange Kyber 768 Draft upgraded to standard Module-Lattice 768.
Changed
INFO. Every logs generated will always be DEBUG level.Fixed
CryptoError instead.Added
Large HTTP headers cannot be encoded to be sent.
Fixed
Changed
Support for informational response 1XX in HTTP/3. The event InformationalHeadersReceived has been added to reflect that.
Added
InformationalHeadersReceived has been added to reflect that.Changed
Support for Post-Quantum KX Kyber768 (NIST Round 3) with X25519.
Added
Changed
ECDSA_SECP256R1_SHA256, RSA_PSS_RSAE_SHA256, RSA_PKCS1_SHA256, ECDSA_SECP384R1_SHA384, RSA_PSS_RSAE_SHA384, RSA_PKCS1_SHA384, RSA_PSS_RSAE_SHA512, RSA_PKCS1_SHA512, ED25519.Fixed
Misc
from __future__ import annotations everywhere in order to simplify type annotations.Bump aws-lc-rs from version 1.7.3 to 1.8.1
Changed
aws-lc-rs from version 1.7.3 to 1.8.1rustls from 0.23.8 to 0.23.12Fixed
Added
Support for Windows ARM64 pre-built wheel in CD pipeline.
Added
Changed
Decryption error after receiving long (quic) header that required key derivation.
Fixed
Further improved the reliability of the qpack encoder/decoder.
Changed
Qpack encoder / decoder failure due to unfed stream data.
Fixed
Buffer management has been migrated over to Rust in order to improve the overall performance.
Changed
Misc
setting assert_hostname to False triggered an error when the peer certificate contained at least one IP in subject alt names.
Fixed
qpack encoder/decoder blocking state in a rare condition.
Fixed
quic and http3 loggers causing a StreamHandler to write into stderr.Changed
PyO3 unsendable classes constraint has been relaxed. qh3 is not thread-safe and you should take appropriate measures in a concurrent environment.
Fixed
Added
CipherSuite and SessionTicket classes in the top-level import.Misc
cryptography dependency removal, solely for Niquests usage.If you rely on one aspect of enumerated breaking changes, please pin qh3 to exclude this major (eg. >=0.15,<1) and inform us on how this release affec…
Removed
cryptography along with the indirect dependencies on cffi and pycparser.H0Connection class that was previously deprecated. Use either urllib3-future or niquests instead.RSA_PKCS1_SHA1 signature algorithm due to its inherent risk dealing with the unsafe SHA1.cryptography. You have to encode them into PEM format.Changed
Added
qh3 (top-level import).Misc
maturin as the build backend.If you rely on one aspect of enumerated breaking changes, please pin qh3 to
exclude this major (eg. >=0.15,<1) and inform us on how this release affected your program(s).
We will listen.
The semantic versioning will be respected excepted for the hazardous materials.
Improved stream write scheduling. (upstream patch https://github.com/aiortc/aioquic/pull/475)
Fixed
Misc
Mitigate deprecation originating from cryptography about datetime naïve timezone.
Changed
_crypto module based on upstream work https://github.com/aiortc/aioquic/pull/457cryptography version to 42.xFixed
cryptography about datetime naïve timezone.Converted our Buffer implementation to native Python instead of C as performance is better thanks to CPython internal optimizations
Changed
Buffer implementation to native Python instead of C as performance is better thanks to CPython internal optimizationsFixed
Added
StopSendingReceived eventopen_outbound_streams in QuicConnectionmax_concurrent_bidi_streams in QuicConnectionmax_concurrent_uni_streams in QuicConnectionget_cipher in QuicConnectionget_peercert in QuicConnectionget_issuercerts in QuicConnectionChanged - Converted our Buffer implementation to native Python instead of C as performance are plain better thanks to CPython internal optimisations
Fixed - Addressed performance concerns when attributing new stream ids - The retry token was based on a weak key
Added - StopSendingReceived event - Property open_outbound_streams in QuicConnection - Property max_concurrent_bidi_streams in QuicConnection - Property max_concurrent_uni_streams in QuicConnection - Method get_cipher in QuicConnection - Method get_peercert in QuicConnection - Method get_issuercerts in QuicConnection
Support for in-memory certificates (client/intermediary) via Configuration.load_cert_chain(..)
Added
Configuration.load_cert_chain(..)Removed
_vendor.OpenSSLAll INFO logs entries are downgraded to DEBUG
Changed
Removed
Deprecated
H0Connection will be removed in the 1.0 milestone. Use HTTP Client Niquests instead.QuicConnection ignored verify_hostname context option (PR #16 by @doronz88)
Fixed
verify_hostname context option (PR #16 by @doronz88)Support for QUIC mTLS on the client side (PR #13 by @doronz88)
Added
Toggle for hostname verification in Configuration
Added
Changed
Support for certificate fingerprint matching
Added
Fixed
Changed
Support for "IP Address" as subject alt name in certificate verifications
Added
Dependency on OpenSSL development headers
Removed
Changed
cryptography OpenSSL binding instead of our own copyAdded
Mitigate ssl.match_hostname deprecation by porting urllib3 match_hostname
Removed
Changed
Fixed
Your coding agent can read these notes before it upgrades. Set up the MCP server →