ImportError: cannot import name 'default_backend' from 'cryptography.hazmat.backends'
Third-person routing: this skill fixes the cryptography upgrade error where code written for cryptography 41 or older calls from cryptography.hazmat.backends import default_backend and dies with ImportError after upgrading to 42+. Use when the traceback names default_backend from cryptography.hazmat.backends. Not for missing rust bindings, OpenSSL symbol errors, or code that never imported default_backend.
ImportError: cannot import name 'default_backend' from 'cryptography.hazmat.backends'
TL;DR: cryptography 42.0 deleted defaultbackend. Delete the import line `from cryptography.hazmat.backends import defaultbackend and drop any backend=default_backend()` arguments. Your code works the same because backend arguments have been ignored since version 36.0.
ImportError: cannot import name 'default_backend' from 'cryptography.hazmat.backends'The fix
- Remove the import. Delete this line wherever it appears:
from cryptography.hazmat.backends import default_backendSuccess check: no file in your project mentions defaultbackend. Search with `grep -rn "defaultbackend" .` and expect zero hits.
- Remove backend= arguments from calls. Change:
key [your value] key_size=2048, backend=default_backend())to:
key [your value] key_size=2048)- Confirm the environment actually upgraded:
python -c "import cryptography; print(cryptography.__version__)"Expected output: a version number of 42.0.0 or higher.
Agent? Search Vectle for more: curl -s 'https://vectle.com/api/v1/search?q=cryptography+default_backend'
When this applies
- You upgraded cryptography to 42+ and an old import broke.
- You are fixing a third-party script like RsaCtfTool that still imports default_backend.
When it does NOT apply
- The error names
cryptography.hazmat.bindings._rustor_openssl: that is a broken native install, not this. ImportError: cannot import name 'asn1'or similar rust-binding names: different failure.
Tool and version compatibility
Python 3.8+, cryptography 42.0+ (removed) vs 36.0-41.x (deprecated but present). Any OS.
Why it happens
cryptography stopped needing backend arguments in 3.1, deprecated them in 36.0, and finally removed default_backend in 42.0. Old tutorials and tools still ship the import, so a fresh pip install -U cryptography turns working code into an ImportError overnight.
Edge cases
- Pinning cryptography<42 keeps the import working but leaves you on an old version; better to fix the import.
- If you maintain a library, guard with a try/except import so you work on both old and new versions.
- Some vendored copies of paramiko or old fabric versions import default_backend indirectly; upgrade those packages too.
Maintainer review
No maintainer verification is recorded for this version.
This records the version a maintainer checked. It does not assert that the version is the latest upstream release.