Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension


Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
13 changes: 13 additions & 0 deletions CHANGES.md
Original file line number Diff line number Diff line change
@@ -1,3 +1,16 @@
# Version 0.16.0.1 - September 23, 2026

- Security fix: the automatic liboqs installation no longer runs commands
through a shell, which allowed command injection via `PYOQS_VERSION` and
the install paths,
https://github.com/open-quantum-safe/liboqs-python/security/advisories/GHSA-pw23-r5gj-42g8
- Added support for the ML-DSA external-mu variants when liboqs provides
them, https://github.com/open-quantum-safe/liboqs-python/pull/154
- Added installation instructions for Windows and Raspberry Pi,
https://github.com/open-quantum-safe/liboqs-python/pull/135
- Releases are now published to PyPI automatically,
https://github.com/open-quantum-safe/liboqs-python/pull/150

# Version 0.16.0 - July 23, 2026

- Updated to liboqs 0.16.0
Expand Down
3 changes: 2 additions & 1 deletion README.md
Original file line number Diff line number Diff line change
Expand Up @@ -105,7 +105,8 @@ This is convenient in case you want to avoid installing liboqs manually, as
described in the subsection above.

By default, liboqs-python installs the liboqs release that matches its own
version. Set the `PYOQS_VERSION` environment variable to override this:
version; a maintenance release such as liboqs-python 0.16.0.1 installs liboqs
0.16.0. Set the `PYOQS_VERSION` environment variable to override this:

```shell
export PYOQS_VERSION=0.16.0 # install a specific liboqs release
Expand Down
35 changes: 24 additions & 11 deletions RELEASE.md
Original file line number Diff line number Diff line change
@@ -1,16 +1,29 @@
# liboqs-python version 0.16.0
# liboqs-python version 0.16.0.1

---

# Added in version 0.16.0
This is a maintenance release of liboqs-python 0.16.0 that fixes a security
issue. It is still built for liboqs 0.16.0. All users of liboqs-python
0.10.0 through 0.16.0 who rely on liboqs being installed automatically
should upgrade.

- Updated to liboqs 0.16.0.
- Added the `PYOQS_VERSION` environment variable to override the liboqs
release that is installed automatically at runtime.
- Fixed the Windows shared library lookup to search for both `oqs.dll` and
`liboqs.dll`.
- Fixed a `StatefulSignature` segfault when liboqs is built without stateful
signature key generation support.
# Security fix in version 0.16.0.1

- **Shell command injection in automatic liboqs installation**
([GHSA-pw23-r5gj-42g8](https://github.com/open-quantum-safe/liboqs-python/security/advisories/GHSA-pw23-r5gj-42g8)).
When liboqs was not found at import time, liboqs-python built it by running
git and CMake through a shell, so shell metacharacters in `PYOQS_VERSION`,
`OQS_INSTALL_PATH`, `HOME`, or `TMPDIR` could execute arbitrary commands.
These commands now run without a shell, and `PYOQS_VERSION` is validated.

# Other changes in version 0.16.0.1

- Fixed automatic installation of liboqs release candidates (e.g.,
`0.16.0-rc1`) and install paths that contain spaces.
- Added support for the ML-DSA external-mu variants when liboqs provides them
(they are not in liboqs 0.16.0).
- Added installation instructions for Windows and Raspberry Pi.
- Releases are now published to PyPI automatically.

## About

Expand All @@ -34,9 +47,9 @@ See in particular limitations on intended use.

## Release notes

This release of liboqs-python was released on July 23, 2026. Its release
This release of liboqs-python was released on September 23, 2026. Its release
page on GitHub is
https://github.com/open-quantum-safe/liboqs-python/releases/tag/0.16.0.
https://github.com/open-quantum-safe/liboqs-python/releases/tag/0.16.0.1.

---

Expand Down
2 changes: 1 addition & 1 deletion pyproject.toml
Original file line number Diff line number Diff line change
@@ -1,7 +1,7 @@
[project]
name = "liboqs-python"
requires-python = ">=3.10"
version = "0.16.1-dev"
version = "0.16.0.1"
description = "Python bindings for liboqs, providing post-quantum public key cryptography algorithms"
authors = [
{ name = "Open Quantum Safe project", email = "contact@openquantumsafe.org" },
Expand Down
Loading