HKDF in cryptography before 1.5.3 returns an empty byte-string if used with a length less than algorithm.digest_size.
{ "nvd_published_at": "2017-03-27T17:59:00Z", "cwe_ids": [ "CWE-20" ], "severity": "HIGH", "github_reviewed": true, "github_reviewed_at": "2022-06-17T21:29:04Z" }