—
RUSTSEC-2026-0069
Incorrect Length Encoding on KDF Export
Details
Passing values `length > 65535` to `Context::export` produces output that disagrees with the RFC 9180 label encoding. In particular the length value is cast to `u16` truncating any value exceeding 65535.
## Impact Applications that use hpke-rs to export very large secrets would experience interoperability issues with other applications that use a correct implementation to export very large secrets.
## Mitigation Starting with version `0.6.0`, an error will be returned when attempting to call `Context::export` with an output length > 65535.
Are you affected?
Enter the version of the package you're using.
Affected packages
crates.io/hpke-rs
Introduced in:
0.0.0-0Fixed in: 0.6.0Upgrade hpke-rs to 0.6.0 or newer (ecosystem crates.io).