VDB
KO

PYSEC-2017-8

Details

HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI / cryptography
Introduced in: 0 Fixed in: b924696b2e8731f39696584d12cceeb3aeb2d874
Fix pip install --upgrade 'cryptography>=b924696b2e8731f39696584d12cceeb3aeb2d874'

References