HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.
"https://github.com/pypa/advisory-database/blob/main/vulns/cryptography/PYSEC-2017-8.yaml"