SMP security request (from peripheral) does not include the maximum encryption key size supported. Using a key with less than the maximum keysize makes brute-forcing the key easier. See V6 in BLERP paper linked below.
https://www.ndss-symposium.org/ndss-paper/blerp-ble-re-pairing-attacks-and-defenses/