# github.com/Masterminds/sprig/v3@v3.3.0 security report (Go)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-05T19:08:23.000Z
- Files reviewed: 14
- Findings: 7 medium, 8 low severity findings
- Report: https://security.togoder.click/go/github.com/Masterminds/sprig/v3
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the Go package github.com/Masterminds/sprig/v3@v3.3.0 on Oct 5, 2026. An AI review of 14 source files produced 7 medium, 8 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Weak cryptography

Finding ID: `NPS-855AE54B97B8`

File: `crypto.go:575`

The encryptAES function uses AES-CBC with a key derived by simply copying the password bytes into a 32-byte buffer (zero-padded if shorter). This lacks proper key derivation (e.g., PBKDF2, scrypt) and uses PKCS#7 padding, making it vulnerable to padding oracle attacks. Additionally, CBC mode without authentication (e.g., HMAC) is susceptible to bit-flipping attacks.

### [medium] Weak cryptography

Finding ID: `NPS-3A7B4B4FC91E`

File: `crypto.go:609`

The decryptAES function performs AES-CBC decryption without verifying integrity or padding correctly (it simply slices off the last byte as padding length without validation), which can lead to panics or padding oracle vulnerabilities.

### [medium] Environment variable access

Finding ID: `NPS-1B6A4636897A`

File: `functions.go:287`

The function map includes 'env' and 'expandenv' which directly call os.Getenv and os.ExpandEnv. This allows template authors to read arbitrary environment variables, which may contain sensitive data such as API keys, tokens, or credentials. While this is a documented feature of the sprig library, it poses a security risk if templates are not fully trusted.

### [medium] Ignored error handling

Finding ID: `NPS-41E8CAC940D6`

File: `network.go:9`

The error returned by net.LookupHost is discarded. If DNS resolution fails (e.g., no such host, network issues), addrs will be nil or empty, causing rand.Intn(0) to panic with 'invalid argument to Intn'. This is a reliability/availability bug rather than a direct security exploit, but can be triggered by invalid input passed to the template function.

### [medium] Potential panic via attacker-controlled input

Finding ID: `NPS-8DD889A60170`

File: `network.go:10`

getHostByName accepts an arbitrary name string and passes it directly to net.LookupHost. A caller (e.g., a template author) supplying a name that fails to resolve will cause a panic on rand.Intn(len(addrs)) since len(addrs)==0, potentially crashing the process if panics are not recovered.

### [medium] Resource exhaustion / ReDoS risk

Finding ID: `NPS-CA319999E960`

File: `regex.go:14`

Regexes are compiled on every call to regexFindAll, regexFind, regexReplaceAll, regexReplaceAllLiteral, and regexSplit via regexp.MustCompile. An attacker-supplied regex can trigger a panic (unrecovered MustCompile on invalid pattern) or cause a denial-of-service via catastrophic backtracking / excessive compilation, since there is no caching or validation. The 'must' variants return errors, but the non-must variants will panic on invalid input.

### [medium] Panic-based denial of service

Finding ID: `NPS-C8EA60D597B6`

File: `regex.go:38`

Functions regexFindAll, regexFind, regexReplaceAll, regexReplaceAllLiteral, and regexSplit call regexp.MustCompile with user-controlled input. A malformed regex will cause a runtime panic, crashing the process or template rendering engine (sprig is commonly used in Helm templates). This is a reliability/DoS concern rather than overt malware.

### [low] Weak cryptographic hash

Finding ID: `NPS-F4D74F5D55A4`

File: `crypto.go:32`

The sha1sum function uses SHA-1, which is cryptographically broken and should not be used for security-sensitive purposes.

### [low] Weak cryptographic hash

Finding ID: `NPS-CD3E6185C197`

File: `crypto.go:37`

The adler32sum function uses Adler-32, which is not a cryptographic hash and provides no security guarantees.

### [low] Predictable randomness

Finding ID: `NPS-F01421B8D252`

File: `crypto.go:103`

The derivePassword function uses a deterministic counter-based approach with HMAC-SHA256 for password generation, which is intended but relies on scrypt with a fixed salt derived from user input. This is by design for Master Password algorithm, but the use of a weak salt (length-prefixed user) could be a concern if the password is weak.

### [low] Potential key exposure

Finding ID: `NPS-7D88F5789A27`

File: `crypto.go:148`

The generatePrivateKey function returns private keys as PEM-encoded strings, which could be logged or exposed if not handled carefully. This is a common utility but requires caution.

### [low] Insecure certificate generation

Finding ID: `NPS-48D5263C1198`

File: `crypto.go:477`

The certificate generation functions (generateCertificateAuthority, generateSelfSignedCertificate, generateSignedCertificate) use RSA 2048-bit keys, which is acceptable but could be stronger. They also set BasicConstraintsValid to true without properly setting IsCA for non-CA certificates, which might lead to misconfigurations.

### [low] Non-hermetic functions explicitly listed

Finding ID: `NPS-E7E28EB56EB5`

File: `functions.go:59`

The code explicitly identifies non-hermetic functions (those that depend on environment, time, or randomness) and provides hermetic variants that exclude them. This is good security practice, but the presence of the non-hermetic functions in the default map remains a potential risk.

### [low] Network-related function

Finding ID: `NPS-72A5376CD3B0`

File: `functions.go:289`

The function map includes 'getHostByName' which performs DNS lookups. This can be used for data exfiltration or network reconnaissance from within a template context.

### [low] Cryptographic operations

Finding ID: `NPS-ACBFECDFB2C4`

File: `functions.go:345`

The function map exposes numerous cryptographic functions including bcrypt, htpasswd, key generation, certificate generation, and AES encryption/decryption. While not inherently malicious, these could be misused to generate keys, encrypt data, or create certificates within a template context.

## Files reviewed

- `crypto.go` (medium): The code contains several cryptographic weaknesses (insecure AES-CBC usage, weak hashes) but no malicious patterns such as data exfiltration or backdoors.
- `functions.go` (medium): The sprig library exposes environment variable access, DNS lookups, and cryptographic functions through its template function map, which could be exploited if untrusted templates are used, but no overtly malicious code was found.
- `network.go` (medium): No malicious code or exfiltration was found, but the function has an unhandled error path that can panic on unresolvable hostnames, posing a minor availability risk.
- `regex.go` (medium): No malicious exfiltration, network, filesystem, or code-execution patterns found; the only concerns are potential denial-of-service/panic issues from user-controlled regex compilation.
- `date.go` (safe): Cleared by Jev triage; no further analysis needed
- `defaults.go` (safe): No malicious patterns detected; the file contains standard template helper functions from the sprig library with no exfiltration, credential harvesting, obfuscation, or suspicious behavior beyond a benign random seed in init().
- `dict.go` (safe): No malicious patterns detected; this is a standard Go template utility library with map manipulation functions.
- `doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `list.go` (safe): Cleared by Jev triage; no further analysis needed
- `numeric.go` (safe): Cleared by Jev triage; no further analysis needed
- `reflect.go` (safe): Cleared by Jev triage; no further analysis needed
- `semver.go` (safe): Cleared by Jev triage; no further analysis needed
- `strings.go` (safe): Cleared by Jev triage; no further analysis needed
- `url.go` (safe): No malicious patterns detected; the code only provides URL parsing and joining functionality typical of the sprig template library.

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
