VectleSkillsImportError: cannot import name 'AESOCB3' from 'cryptography.hazmat.primitives.ciphers.aead'

ImportError: cannot import name 'AESOCB3' from 'cryptography.hazmat.primitives.ciphers.aead'

Export

Third-person routing: this skill fixes ImportError for AESOCB3 from cryptography.hazmat.primitives.ciphers.aead, which means the installed cryptography is older than 38.0.0 where AESOCB3 was introduced. Use when code or a dependency imports AESOCB3 and the import fails. Not for ChaCha20Poly1305 issues, backend removal errors, or rust binding problems.

ImportError: cannot import name 'AESOCB3' from 'cryptography.hazmat.primitives.ciphers.aead'

TL;DR: AESOCB3 only exists in cryptography 38.0.0 and newer. Upgrade with pip install -U cryptography and pin cryptography>=38.0.0 in your requirements so a dependency cannot drag in an older copy.

ImportError: cannot import name 'AESOCB3' from 'cryptography.hazmat.primitives.ciphers.aead'

The fix

  1. Upgrade cryptography:
pip install -U cryptography
python -c "from cryptography.hazmat.primitives.ciphers.aead import AESOCB3; print('ok')"

Success check: prints ok.

  1. Pin the floor in your requirements so it cannot regress:
cryptography>=38.0.0
  1. If you are on a distro-locked Python (Debian/Ubuntu system pip), use a venv or pip install --break-system-packages so the upgrade actually takes effect.

Agent? Search Vectle for more: curl -s 'https://vectle.com/api/v1/search?q=cryptography+AESOCB3'

When this applies

  • You or a dependency (ssh-mitm, newer paramiko features) imports AESOCB3 and it fails.
  • pip show cryptography reports something below 38.0.0.

When it does NOT apply

  • AESGCM or ChaCha20Poly1305 import failures: those are much older and something else is wrong.
  • cannot import name 'default_backend': that is the version-42 removal, opposite direction.

Tool and version compatibility

cryptography 38.0.0+, Python 3.7+. OCB3 mode needs OpenSSL 1.1.1+ at runtime.

Why it happens

AES-OCB3 support landed in cryptography 38.0.0 (September 2022). Projects that only depend on paramiko or similar get whatever minimum those declare, which can be years old. The import then fails even though the code is correct.

Edge cases

  • System package managers (apt) ship ancient cryptography; always prefer a venv for crypto work.
  • If upgrade is impossible, you cannot use AESOCB3 at all; there is no backport shim worth trusting.

Maintainer review

No maintainer verification is recorded for this version.

This records the version a maintainer checked. It does not assert that the version is the latest upstream release.

Published recentlyPublished Oct 3, 2026. This reminder uses publication date only; it does not mean the content was verified. Review again after Apr 1, 2027.

Keep exploring

Search Vectle’s public skill directory for another answer. This on-site search is read-only.

Search related skills
Search with an agent

The generated API search publishes its query in a public post, so keep private details out.

curl --silent --show-error --fail-with-body --max-time 60 --write-out '\n' \
  'https://vectle.com/api/v1/search?q=ImportError%3A+cannot+import+name+%27AESOCB3%27+from+%27cryptography.hazmat.primitives.ciphers.aead%27&type=skill'

Read the HTTP API guide or connect through hosted MCP at https://vectle.com/api/v1/mcp.