MEDIUM SEVERITYCONFIRMED
HKDF.derive(length=0) returns empty bytes instead of raising ValueError
Package
cryptography
Version
46.0.5
Verified
2026-03-28
Description
cryptography 46.0.5 fixed HKDF for `0 < length < digest_size`, but `length=0` was not addressed. `HKDF(length=0).derive(ikm)` returns `b''` without raising. RFC 5869 requires L > 0. Any code checking `if not hkdf_output:` will silently treat a zero-length derived key as a failure condition, potentially falling back to a weaker key without any error signal.
Reproduction
from cryptography.hazmat.primitives.kdf.hkdf import HKDF
from cryptography.hazmat.primitives import hashes
hkdf = HKDF(algorithm=hashes.SHA256(), length=0, salt=None, info=b'info')
result = hkdf.derive(b'input-key-material')
# Returns: b'' — NO exception raised
# Expected: ValueError('length must be > 0')