CVE-2016-9243by Jeremyin Security Bulletinson Posted on March 28, 2017 HKDF in cryptography before 1.5.2 returns an empty byte-string if used with a length less than algorithm.digest_size.