py-tlsh
TLSH (C++ Python extension)
Decision gist · record as of 2026-08-14
Yes, if you need fuzzy matching on binary data and can tolerate C++ compilation at install time. The package is actively maintained, permissively licensed, has no known vulnerabilities, and solves a specific problem well. The high install friction is the main trade-off—ensure your deployment environment has build tools available before adopting it.AI-flagged interpretation of the facts on this page — verify before relying
Before you install
- Data must be bytes (not string), and minimum 50 bytes with sufficient complexity required for hash generation; C++ extension compilation needed at install time.
- High install friction due to C++ extension compilation required.
- Package is actively maintained with recent commits and no known vulnerabilities, but the compiled dependency means build tools and headers must be present on the target system.
License · maintenance · safety
Apache or BSD (permissive) — Licensed under Apache or BSD (permissive), so commercial and proprietary use is permitted without restriction or copyleft obligation.
last release 2026-05-08 (98 days) · last repo commit 2026-07-10 · 844 stars
0 known vulnerabilities (OSV.dev, 2026-08-14) · 102,139 downloads/mo, #12,886 on PyPI
Alternatives
Verify before relying
import tlsh
# Hash binary data (minimum 50 bytes recommended)
h1 = tlsh.hash(data)
h2 = tlsh.hash(similar_data)
# Compare hashes for similarity
score = tlsh.diff(h1, h2)- Whether the C++ extension builds reliably on all major platforms despite the 'OS Independent' classifier
- Performance characteristics and hash collision rates for real-world binary data
- Whether the memory leak fixes in 4.12.1 fully resolved the reported issues
What it is and what it does
py-tlsh is a Python binding to the TLSH (Trend Micro Locality Sensitive Hash) C++ library, a fuzzy matching algorithm designed for binary data. It generates hash values from byte streams that preserve similarity—similar inputs produce similar hashes—enabling detection of related objects by comparing hash values rather than doing byte-for-byte comparison. The library requires a minimum of 50 bytes of input with sufficient randomness to generate a valid hash; it will not hash uniform or near-uniform data.
The package is a C++ extension, so installation requires compilation on the target system. It provides both simple one-shot hashing via tlsh.hash() and streaming hashing via the Tlsh class for processing large files incrementally. It supports multiple hash formats including the current T1 format and older formats for backwards compatibility, and offers variants like diffxlen() for length-independent comparison and conservativehash() for stricter randomness requirements.
Use it for
- Detect similar malware samples or suspicious files by comparing TLSH hashes instead of exact signatures
- Find near-duplicate documents or data blobs in large datasets without full content comparison
- Stream-hash large files incrementally to avoid loading entire contents into memory
- Compare binary artifacts with length-independent similarity scoring using diffxlen()
- Maintain compatibility with legacy systems using older TLSH hash formats via oldhash()
Worth the install?
AI-flagged interpretation of the facts on this page. Verify before relying on it.
Yes, if you need fuzzy matching on binary data and can tolerate C++ compilation at install time.
The package is actively maintained, permissively licensed, has no known vulnerabilities, and solves a specific problem well. The high install friction is the main trade-off—ensure your deployment environment has build tools available before adopting it.
Install
py-tlsh on PyPI
Before you install
High install friction due to C++ extension compilation required. Package is actively maintained with recent commits and no known vulnerabilities, but the compiled dependency means build tools and headers must be present on the target system.
Data must be bytes (not string), and minimum 50 bytes with sufficient complexity required for hash generation; C++ extension compilation needed at install time.
License in practice
Licensed under Apache or BSD (permissive), so commercial and proprietary use is permitted without restriction or copyleft obligation.
Quickstart
import tlsh
# Hash binary data (minimum 50 bytes recommended)
h1 = tlsh.hash(data)
h2 = tlsh.hash(similar_data)
# Compare hashes for similarity
score = tlsh.diff(h1, h2)
Verify before relying
- Whether the C++ extension builds reliably on all major platforms despite the 'OS Independent' classifier
- Performance characteristics and hash collision rates for real-world binary data
- Whether the memory leak fixes in 4.12.1 fully resolved the reported issues
Package facts
| License | Apache or BSD permissive |
| Python support | Supports the current Python release >=2.7 |
| Install friction | High. Source build required |
| Runtime dependencies | None |
| Maintenance | Actively maintained 98 days since the last release |
| Last repo commit | |
| First released | |
| Downloads | 102,139 / month, #12,886 on PyPI 30-day window, as of 2026-08-14 |
| Known vulnerabilities | None known OSV.dev, checked 2026-08-14 |
| Classifiers | Development Status :: 5 - Production/StableIntended Audience :: DevelopersNatural Language :: EnglishOperating System :: OS IndependentProgramming Language :: Python :: 2.7 |
Evidence: py_tlsh-5.0.0.tar.gz
Tags
Let your AI agent find packages like this
Example. Real query, live index.
You found this page by searching. An agent finds it by wishing: SkillFed indexes 14,416 PyPI packages by what they can do, searchable in plain language.
wish › “fuzzy matching binary data”
- py-tlshGenerates locality-sensitive hashes for fuzzy matching of binary…
- fuzzysearchFinds approximate substring matches in text or data with configurable…
- fuzzyset2Performs fuzzy string matching and approximate searching against a…
Give your agent the search over MCP, or paste the wish link into any chat.
More Information Analysis packages
A drop-in replacement for Python's standard `re` module that adds advanced regex features like nested sets, fuzzy matching, lookaround in conditionals, and full Unicode case-folding while maintaining backward compatibility.
pyarrow provides Python bindings to Apache Arrow's C++ libraries for efficient columnar data processing, serialization, and interoperability with pandas, NumPy, and other Python ecosystem tools.
NetworkX provides data structures and algorithms for creating, analyzing, and manipulating graphs and networks, supporting everything from simple undirected graphs to complex directed and weighted networks.
Connects Python applications to Snowflake data warehouses using the DB API 2.0 specification, enabling SQL queries, data transfers, and warehouse operations.
ContourPy calculates contours of 2D quadrilateral grids using C++11 algorithms wrapped in Python, offering serial and multithreaded implementations without requiring Matplotlib as a dependency.
Snowpark Python provides APIs to query and process data directly in Snowflake without moving data to your local system, with support for both native Snowpark and pandas-compatible interfaces.
Install it if you use Snowflake and want to process data without moving it to your application layer.
See also ppdeep · pysimstring · ImageHash · simhash · rensa · tfidf-matcher · ngram · py-multihash · filehash · polars-hash