VDB
Sign up
—

RUSTSEC-2026-0069

Incorrect Length Encoding on KDF Export

Details

Passing values `length > 65535` to `Context::export` produces output that disagrees with the RFC 9180 label encoding. In particular the length value is cast to `u16` truncating any value exceeding 65535.

## Impact Applications that use hpke-rs to export very large secrets would experience interoperability issues with other applications that use a correct implementation to export very large secrets.

## Mitigation Starting with version `0.6.0`, an error will be returned when attempting to call `Context::export` with an output length > 65535.

Are you affected?

Enter the version of the package you're using.

Affected packages

crates.io/hpke-rs
Introduced in: 0.0.0-0Fixed in: 0.6.0

Upgrade hpke-rs to 0.6.0 or newer (ecosystem crates.io).

References