Togoder security

Go package security report

github.com/bytedance/sonic Go module: is it safe?

Risky patterns found that deserve a look.

Needs review Version v1.15.4 Files reviewed 290 Size 8.8 MB Scanned

Summary

Togoder Security scanned the Go package github.com/bytedance/sonic@v1.15.4 on Oct 5, 2026. An AI review of 290 source files produced 63 medium, 67 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
63
medium
67
low

Findings 130

medium

unsafe pointer usage

NPS-84F0F5743F99

Extensive use of unsafe.Pointer and pointer arithmetic (e.g., rt.UnpackEface, (*rt.GoString)(unsafe.Pointer(&self.s)), native.Value calls with raw pointers) bypasses Go's memory safety guarantees. While typical for high-performance JSON libraries, this increases the risk of memory corruption or exploitable bugs if the native code has flaws.

ast/api.go
medium

native code interaction

NPS-568CC3753626

Calls to internal/native functions (native.Value, native.SkipOne, native.SkipOneFast, native.GetByPath) execute platform-specific assembly or C code that is not visible in this file. Such native code could contain hidden malicious behavior or vulnerabilities that cannot be audited from the provided source alone.

ast/api.go
medium

Unsafe memory operations

NPS-D077DF8EBF56

Extensive use of unsafe package with //go:nocheckptr directives and direct pointer arithmetic to bypass bounds checking. While typical for performance-critical JSON parsing libraries, this significantly increases risk of memory corruption if inputs are not perfectly validated. The skipBlank, decodeInt64, decodeFloat64, skipString, and skipPair functions manipulate pointers directly without bounds verification.

ast/decode.go
medium

Potential out-of-bounds read in skipString

NPS-C6ABE1F63868

In skipString, when encountering a backslash escape character, the code does 'sp += 2' without checking if sp+1 is still within bounds. This could read past the end of the string buffer if a string ends with an unescaped backslash near the buffer boundary.

ast/decode.go:318
medium

Potential out-of-bounds read in skipPair

NPS-8F1928D91837

In skipPair, when encountering a backslash, the code does 'sp += 2' without verifying sp+1 remains within the buffer bounds, potentially reading beyond the allocated memory.

ast/decode.go:361
medium

Unsafe pointer usage

NPS-CB08063BD2E9

The code uses unsafe.Pointer to store a pointer to a local string variable in newError and newSyntaxError. The string variable 'msg' is allocated on the stack and its address is taken. After the function returns, the pointer stored in the Node struct points to a stack location that may be reused or invalidated, leading to a dangling pointer. When Error() dereferences this pointer later, it can cause memory corruption, crashes, or potentially leak sensitive information from other stack frames. This is a memory safety issue that could be exploited.

ast/error.go:11
medium

Unsafe pointer usage

NPS-6B427C6514BC

Similar unsafe.Pointer issue in newSyntaxError: the local variable 'msg' is stored via unsafe.Pointer in the Node returned. The pointer becomes invalid after function return, causing undefined behavior when Error() is later called.

ast/error.go:30
medium

Unsafe pointer usage

NPS-18B2DD4286F2

In unwrapError, when err is not *Node or Node, a local variable 'msg' is created and its address stored via unsafe.Pointer in a new Node. This again creates a dangling pointer after function return, leading to potential memory safety issues.

ast/error.go:50
medium

Unsafe memory manipulation

NPS-1643D5F06290

The mem2ptr function uses the unsafe package to convert a byte slice to an unsafe.Pointer by accessing internal runtime slice representation. This bypasses Go's type safety and could lead to memory corruption, out-of-bounds access, or undefined behavior if used improperly. The //go:nosplit directive prevents stack growth checks, further increasing risk. While this appears to be a legitimate utility for a high-performance JSON library (Sonic), unsafe pointer manipulation is a common vector for exploitation if the library is compromised or if callers misuse the function.

ast/stubs.go:22
medium

Dynamic code execution / JIT compilation

NPS-05E4EC5AB311

This file is part of a JIT (Just-In-Time) code assembler that generates and executes native x86-64 machine code at runtime. It uses the golang-asm library to emit raw assembly instructions, construct executable machine code, and jump to dynamically generated code addresses. While this is a legitimate performance optimization for the sonic JSON decoder, JIT compilation is a dual-use capability that could be abused to execute arbitrary code if the instruction stream is attacker-controlled. The _Program instruction stream originates from internal decoder logic, not external input, but the mechanism itself is a high-risk pattern.

internal/decoder/jitdec/assembler_regabi_amd64.go
medium

Unsafe memory operations / direct machine code emission

NPS-0D35822EC497

The assembler emits raw machine code bytes directly (e.g., self.Byte(0xcc) for INT3 debug breakpoints, self.Byte(0x4c, 0x8d, 0x0d) for LEAQ instructions) and uses unsafe.Pointer extensively. The _asm_OP_debug function emits an INT3 (0xcc) breakpoint instruction. While these are standard for a JIT assembler, direct byte emission and unsafe pointer arithmetic bypass Go's memory safety guarantees and could lead to memory corruption if the generated code is incorrect.

internal/decoder/jitdec/assembler_regabi_amd64.go
medium

Unsafe pointer operations

NPS-AA3D4B9A842C

The code uses unsafe.Pointer extensively with type-unsafe memory reinterpretation, including crafting slices from raw pointers in vs() and reconstructing Go structures from raw memory. While this is typical for JIT/compiler-style JSON decoders like sonic, it is inherently dangerous and could enable memory corruption if fed untrusted input that manipulates the compiled instruction stream.

internal/decoder/jitdec/compiler.go:235
medium

Unsafe memory manipulation

NPS-77B2C89DA31C

The embeddedFieldPtrDecoder.FromDom function performs raw pointer arithmetic using unsafe.Pointer and uintptr to walk struct fields. This is inherent to the library's design (it is part of sonic, a high-performance JSON library by bytedance that uses unsafe for speed), but it carries memory-safety risk if field metadata is inconsistent. No malicious intent detected.

internal/decoder/optdec/functor.go:49
medium

unsafe pointer/reflection usage

NPS-0405AF1A723C

The decoder heavily uses unsafe.Pointer, PtrOffset, rt.Mapassign, and related low-level runtime/reflection primitives to build Go maps from JSON AST nodes. While this is a known performance pattern in libraries like sonic (ByteDance), it bypasses Go's type safety guarantees. Incorrect handling of key memory layouts (e.g., for pointer-key map types) could lead to memory corruption or crashes if inputs are adversarial. The code also depends on runtime internals (rt.GoMapType, rt.Mapassign) that can vary across Go versions.

internal/decoder/optdec/map.go
medium

type confusion potential via unsafe casts

NPS-AEC63EC4D87B

Several decoder methods use unsafe casts like *(*unsafe.Pointer)(vp) = nil and *(*uint32)(unsafe.Pointer(&key)) with assumptions about the underlying type layout (e.g., mapI32KeyDecoder). If the mapType metadata does not match the actual destination type (e.g., through reflection misuse by callers), this could result in memory corruption rather than a safe type error.

internal/decoder/optdec/map.go
medium

unsafe pointer and memory manipulation

NPS-F2C3DB6DB22B

The code makes extensive use of the unsafe package, performing pointer arithmetic, manual memory allocation via rt.Mallocgc, rt.Memmove, and type punning (rt.UnpackType, rt.Str2Mem, rt.Mem2Str). While this is typical for high-performance JSON parsers and not inherently malicious, it creates memory-safety risks including potential out-of-bounds reads/writes that could be exploited if the native parser (native.ParseWithPadding) is fed crafted input.

internal/decoder/optdec/native.go:120
medium

dynamic memory allocation based on input size

NPS-245BE837ECBB

In Parser.parse(), a new node buffer is allocated with size derived from the remaining JSON length (calMaxNodeCap). If jsonSize is extremely large, this can lead to excessive memory allocation, a potential denial-of-service vector when parsing untrusted JSON input.

internal/decoder/optdec/native.go:165
medium

unsafe memory operations

NPS-9C8C0613B600

Extensive use of unsafe.Pointer, uintptr, ptrCast, and //go:nocheckptr for direct memory manipulation without bounds or safety checks. While typical for high-performance JSON parsers, this pattern can lead to memory corruption, out-of-bounds reads/writes, and potential exploitation if input parsing logic has flaws.

internal/decoder/optdec/node.go
medium

manual stack management

NPS-07A9CA64EF03

Custom boundedStack implementation with direct index arithmetic and unsafe.Pointer storage. Missing bounds checks on index (e.g., Pop decrements index without verifying > 0, Push increments without verifying < len). Could cause stack underflow/overflow leading to memory corruption.

internal/decoder/optdec/node.go
medium

memory pool manipulation

NPS-C61C2D945B43

efacePool allocates and reuses memory via unsafe operations. GetMap/GetSlice use unsafe.Pointer conversions; ConvTSlice/ConvF64 etc. write directly to interface slots. If pool sizing (from untrusted JSON stats) is wrong, buffer overflows may occur.

internal/decoder/optdec/node.go
medium

direct memory writes to interface

NPS-3A212A5125E6

AsEfaceFast writes to map/slice interface slots using rt.Mapassign_faststr and direct *vt = ...; *vp = ... assignments. Combined with manual pointer arithmetic (rt.PtrAdd), this bypasses Go's type safety and could corrupt memory if node structure assumptions are violated.

internal/decoder/optdec/node.go
medium

Extensive use of unsafe pointer arithmetic

NPS-FF869F6DE57F

The file heavily relies on the unsafe package and raw pointer arithmetic (e.g., unsafe.Pointer(uintptr(elems) + uintptr(i)*d.elemType.Size)) to manually compute element addresses in slices and arrays. While this is typical for high-performance decoders, it bypasses Go's memory safety guarantees. If the size/type calculations are ever incorrect or inputs are malformed, this could lead to out-of-bounds memory access, memory corruption, or potential exploitation. The //go:nocheckptr directive in arrayDecoder.FromDom further disables runtime pointer checks, increasing the risk surface. No direct malicious intent is evident, but the pattern warrants caution and careful auditing.

internal/decoder/optdec/slice.go
medium

Unsafe pointer arithmetic

NPS-FF6F568F9DF9

The Stack type implements manual stack pointer arithmetic using unsafe.Pointer and uintptr (Top/Cur/Push/Pop). If sp is corrupted or the slab size assumptions are violated, reads/writes could occur out of bounds of the sb array, leading to memory corruption.

internal/encoder/vars/stack.go
medium

Memory clearing via unsafe

NPS-6A97550BAA5C

ResetStack uses rt.MemclrNoHeapPointers over an assumed StackSize. If StackSize is incorrect, this could clear beyond the object and corrupt adjacent heap memory.

internal/encoder/vars/stack.go
medium

Pointer retention in pooled objects

NPS-48EEDB31C74C

Pop sets *st = State{} but Push stores raw unsafe.Pointer values (p, q) into the stack. FreeStack only resets sp and returns the Stack to the pool; it does not clear the sb array, so stale unsafe.Pointer values may be reused, creating potential use-after-free semantics if those pointers are read later.

internal/encoder/vars/stack.go
medium

Use of go:linkname to runtime internals

NPS-174B3D4DE03B

The file uses //go:linkname to access unexported runtime functions (runtime.checkptrBase, runtime.findObject). This is a fragile and dangerous pattern that bypasses Go's type safety and can break between Go versions. While used here for debugging pointer checks, it violates encapsulation and could be misused for memory manipulation.

internal/encoder/x86/debug_go117.go:88
medium

Unsafe pointer manipulation

NPS-EA2F4CC130A0

The code uses unsafe.Pointer and uintptr conversions to inspect pointers (checkptr, findobj). This is inherently unsafe and can lead to memory corruption or information disclosure if pointer values are printed or manipulated incorrectly.

internal/encoder/x86/debug_go117.go:129
medium

JIT code generation and execution

NPS-24873ADE1714

The file is part of a JIT (Just-In-Time) assembler that dynamically generates and loads executable machine code into memory. While this is a legitimate part of the Sonic JSON library for performance, runtime code generation can be abused if the assembler input is not strictly controlled. The presence of a custom loader (loader.LoadOne) that maps generated machine code into executable memory is a high-risk pattern if inputs can be influenced externally.

internal/jit/assembler_amd64.go
medium

Dynamic memory manipulation

NPS-142E64532BC0

Functions like Byte, From, Emit, and resolve directly manipulate memory and patch machine code at runtime. This low-level memory access can be used to bypass security mechanisms or execute arbitrary instructions if the assembler is fed untrusted input.

internal/jit/assembler_amd64.go
medium

Dynamic code generation / JIT compilation

NPS-B330804ED1A1

This file is part of a JIT backend that assembles x86 machine code at runtime using golang-asm. It constructs executable code directly into memory (sym.P) and returns it for execution. While this is the intended purpose of the library (sonic JSON JIT), dynamic code generation inherently carries risk if input is attacker-controlled. The code itself does not appear malicious, but any vulnerability in the assembler or caller could lead to arbitrary code execution.

internal/jit/backend.go
medium

Dynamic code generation / JIT

NPS-CBDB982AF1C6

File is part of a JIT runtime (github.com/bytedance/sonic/internal/jit) that emits machine code at runtime using golang-asm. While not malicious on its own, dynamic code generation can be abused to execute obfuscated payloads and is a common vector for advanced threats.

internal/jit/runtime.go
medium

Unsafe pointer manipulation

NPS-23C214F058A9

The code uses unsafe.Pointer and direct uintptr conversions to obtain raw addresses of runtime types (GoType), itabs, and function values. This bypasses Go's type safety and could be leveraged to corrupt memory or construct arbitrary jump targets if the surrounding JIT engine is misused or fed untrusted input.

internal/jit/runtime.go:37
medium

Dynamic function pointer indirection with unsafe.Pointer

NPS-4178931BED26

The function F_f64toa is declared as a package-level function variable and S_f64toa as a package-level uintptr. These are presumably assigned at init time or via linking to native assembly code. The use of unsafe.Pointer with rt.NoEscape to call an indirect function pointer is a common pattern in high-performance libraries but also could be used to hide malicious native code execution. This file alone does not contain the assignment, making the ultimate behavior opaque from this file.

internal/native/avx2/f64toa.go:28
medium

External function pointer assignment

NPS-9B8C0E883C0E

The variable F_i64toa is declared and expected to be assigned at runtime by native assembly code. If an attacker can control the assignment of this function pointer (e.g., via a malicious binary or improper initialization), it could lead to arbitrary code execution. However, in the context of the ByteDance sonic library, this is a standard pattern for SIMD-optimized routines.

internal/native/avx2/i64toa.go:31
medium

Use of unsafe pointers

NPS-4E1CB7729083

The code uses unsafe.Pointer for low-level memory access. While this is common in performance-optimized libraries and appears legitimate for SIMD/AVX2 operations, it bypasses Go's memory safety guarantees and could lead to memory corruption if misused.

internal/native/avx2/quote.go:28
medium

unsafe pointer usage

NPS-6DFB9A61BE08

Use of unsafe.Pointer and rt.NoEscape to pass a *string to an external function pointer without memory layout guarantees. This bypasses Go's type safety and could lead to memory corruption if the underlying assembly/native implementation mishandles the pointer.

internal/native/avx2/validate_utf8_fast.go:29
medium

unsafe pointer usage and linkname directives

NPS-44727520DC4A

The file heavily uses //go:linkname to bind to assembly functions and unsafe.Pointer for memory access. While this is a legitimate optimization pattern in the Sonic JSON library, it bypasses Go's type safety and could lead to memory corruption if the linked functions are not correctly implemented. This is not inherently malicious but represents a high-risk coding pattern.

internal/native/dispatch_arm64.go
medium

unsafe pointer usage

NPS-2F7B82AC65B6

The code uses the unsafe package and passes raw pointers to a function pointer loaded from a native assembly implementation, which could potentially allow memory corruption if the native code is not properly implemented or validated.

internal/native/sse/i64toa.go:34
medium

Native code execution via loader.WrapGoC

NPS-D4084FF40E6F

This file binds Go function stubs to C functions contained in source files like sse/f64toa.c, sse/parse_with_padding.c, etc. The loader package dynamically links and executes native code at runtime. While this is a standard pattern for high-performance SIMD libraries like sonic, it introduces a trust boundary: the bundled C code could perform arbitrary operations (file system access, network calls, process spawning) that would not be visible in this Go file. The security of the package depends entirely on the integrity of the referenced .c files and the loader implementation.

internal/native/sse/native_export.go
medium

Import-time code registration

NPS-7AA5EDBD9E65

The Use() function registers numerous native C functions with the Go runtime via loader.WrapGoC. If Use() is invoked during package initialization (or from an init() in the same package), native code paths become active before any application-level validation. This matches the red-flag category 'code that runs at install, build or import time'.

internal/native/sse/native_export.go:27
medium

unsafe pointer usage

NPS-8B44ADD647B4

The use of the unsafe package to pass string and int pointers to a native function (F_skip_one_fast) bypasses Go's type safety. Although this is a common pattern in high-performance libraries (e.g., bytedance/sonic), it could theoretically be exploited if the native function is malicious or if pointers are misused to cause memory corruption. The function rt.NoEscape explicitly prevents escape analysis, which is typical for avoiding allocations but can obscure pointer lifetimes.

internal/native/sse/skip_one_fast.go:33
medium

native function call

NPS-27B5DD03FD09

The call to F_skip_one_fast, a function pointer likely set during initialization, executes native code. While not inherently malicious, this pattern can be used to execute arbitrary native code if the function pointer is overwritten by an attacker or if the library is compromised. No evidence of such tampering in this file.

internal/native/sse/skip_one_fast.go:34
medium

Generated code without source

NPS-E456387DD0C5

The file is marked 'Code generated by scripts, DO NOT EDIT' and only declares a symbol pointer to an externally supplied implementation (S_validate_utf8_fast). The actual executable behavior comes from an unresolved native symbol, meaning the auditable surface here is incomplete and the true implementation cannot be reviewed in this file.

internal/native/sse/validate_utf8_fast.go:28
medium

Unsafe code / FFI bridge

NPS-427E181A43BD

This file uses unsafe.Pointer and runtime linkage (rt.NoEscape, function pointer F_validate_utf8_fast populated from a native/assembly implementation) to call platform-specific UTF-8 validation code. While this is typical for performance libraries like Sonic, the package replaces a safe Go implementation with a native call visible only through symbol pointers, which complicates static auditing and can be used to hide behavior outside the Go source tree.

internal/native/sse/validate_utf8_fast.go:31
medium

native function binding

NPS-3EDCF38B4B0E

The variable F_vstring is declared as a function pointer but not assigned in this file. It is likely populated at runtime via dynamic linking or assembly linkage, which introduces a risk of loading untrusted native code if the linkage mechanism can be influenced by external inputs or environment. This pattern is common in performance-critical libraries but should be audited to ensure the symbol resolution is secure.

internal/native/sse/vstring.go:23
medium

unsafe pointer usage

NPS-34A7621971EA

The code uses the unsafe package to pass Go pointers directly into a native function (F_vstring). Although the //go:nosplit directive and rt.NoEscape wrapper are intended to prevent heap escape analysis, this pattern bypasses Go's memory safety guarantees. If the native function retains any of these pointers or misuses the JsonState structure, it could lead to memory corruption, information disclosure, or arbitrary code execution.

internal/native/sse/vstring.go:27
medium

unverified dependency / supply chain risk

NPS-133DABAE7B3A

The code imports github.com/cloudwego/base64x, a third-party package, and directly uses its encoding functions and internal symbols. If this dependency is compromised, it could lead to arbitrary code execution or data exfiltration during base64 encoding/decoding operations. The use of //go:linkname increases the attack surface by allowing access to unexported functions that may not be intended for external use.

internal/rt/base64_amd64.go:5
medium

unsafe linkage / linkname usage

NPS-7457A02B93CF

The file uses //go:linkname to reference unexported symbols (_subr__b64decode and _subr__b64encode) from the github.com/cloudwego/base64x package. This bypasses Go's type safety and encapsulation, creating a fragile and potentially exploitable dependency on internal implementation details. If the base64x package changes its internal symbols, this could cause undefined behavior or crashes. While not inherently malicious, this technique is often used to access hidden functionality.

internal/rt/base64_amd64.go:41
medium

Unsafe pointer arithmetic and memory manipulation

NPS-FA7000489916

The code uses unsafe.Pointer and direct memory manipulation (GoEface, GoSlice, Mallocgc) to convert values into interface{} representations. This bypasses Go's type safety and could lead to memory corruption, crashes, or arbitrary code execution if an attacker can influence the types or values passed to these functions. Functions like Conv, ConvNum, and ConvT64 write directly to memory addresses without bounds checking.

internal/rt/fastconv.go
medium

Use of internal/runtime-specific symbols

NPS-E53BA74E2C89

The code references internal types like GoEface, GoSlice, GoType, Mallocgc, BytesType, StringType, JsonNumberType, Uint64Type, and BoolType that are not part of the public Go standard library. These are copied from runtime internals and are version-specific. Using such internals can cause undefined behavior, crashes, or security issues when the Go runtime changes, and may be exploited if the expected memory layout differs.

internal/rt/fastconv.go
medium

Unsafe reflection and runtime internals manipulation

NPS-FE60E31FEB87

The file uses unsafe.Pointer extensively to reinterpret Go reflect.Type and interface internals, including direct memory layout assumptions (GoType, GoIface, GoEface, GoItab). It also uses go:linkname to access the runtime internal function runtime.getitab. This bypasses Go's type safety and relies on unstable runtime internals, which is fragile and can lead to memory corruption or arbitrary memory access if types are mismatched. While this is a known pattern in high-performance JSON libraries like Sonic (ByteDance), it presents a significant security risk if untrusted input influences the types being manipulated.

internal/rt/fastvalue.go
medium

Use of unsafe and linkname to access runtime internals

NPS-82C4AB346063

The code uses //go:linkname to directly access unexported runtime functions and variables (runtime.gcWriteBarrier2 and runtime.writeBarrier). This bypasses Go's type safety and encapsulation, and relies on internal runtime implementation details that may change across Go versions. It also uses the unsafe package for pointer arithmetic and memory access. While this may be legitimate for low-level runtime manipulation, it is a red flag because such techniques are commonly used in malicious code to hide behavior or manipulate runtime state.

internal/rt/gcwb.go:27
medium

Runtime memory inspection and instruction decoding

NPS-42EBDB85B82D

The GcwbAddr function disassembles machine code at runtime using x86asm to locate the writeBarrier variable by scanning for a specific instruction pattern (CMP with memory operand and zero immediate). This involves reading and interpreting raw memory within the Go runtime, which is highly unusual for normal application code and could be used to locate and modify critical runtime structures.

internal/rt/gcwb.go:47
medium

Unsafe Go directive (go:linkname)

NPS-05022FCA28FD

The file uses the //go:linkname compiler directive to access unexported runtime internals (runtime.gcWriteBarrier, runtime.writeBarrier) from the standard library. This is a fragile and undocumented mechanism that bypasses Go's type and package safety guarantees. While this specific usage appears to be a legitimate low-level GC write barrier implementation (consistent with ByteDance/Sonic high-performance JSON library patterns), linkname access to runtime symbols can be abused by malicious packages to modify or read internal runtime state, hook memory management, or escape sandboxed execution contexts.

internal/rt/gcwb_legacy.go:24
medium

Use of unsafe package and runtime internals

NPS-CC89EDC480B1

The code uses the unsafe package and //go:linkname to access the unexported runtime.growslice function. This bypasses Go's type safety and internal runtime encapsulation. While this is a legitimate performance optimization technique used by packages like Sonic (ByteDance), it directly manipulates memory layout and relies on runtime internals that could change between Go versions, potentially leading to memory corruption or crashes.

internal/rt/growslice.go:22
medium

Runtime implementation dependency

NPS-15DE8661CA78

The //go:linkname growslice runtime.growslice directive depends on the exact signature and behavior of an internal runtime function. If the Go runtime implementation changes (e.g., growslice signature or GoSlice/GoType layout changes), this could cause undefined behavior, memory corruption, or arbitrary memory writes. This is a legitimate but risky pattern.

internal/rt/growslice.go:22
medium

Unsafe runtime linkname usage

NPS-15B9AD6D7DD2

The file uses //go:linkname to bind GrowSlice directly to runtime.growslice, an undocumented internal runtime symbol. This bypasses Go's type safety and version compatibility guarantees. While this pattern is common in performance-oriented libraries (this appears to be from ByteDance's sonic JSON library), linkname to runtime internals can break across Go versions, can be used to circumvent memory safety, and is difficult to audit for malicious behavior. In this file, no exfiltration, credential harvesting, network calls, subprocess execution, init() side effects, or obfuscated payloads are present, so the immediate risk is low; however, the same mechanism could be abused in a malicious variant.

internal/rt/growslice_legacy.go:24
medium

Unsafe memory manipulation

NPS-69C24103DE62

The code uses unsafe.Pointer and manual pointer arithmetic without bounds checking. This can lead to memory corruption, arbitrary memory read/write, or crashes if inputs are not validated. The GetSlice method does not verify that the requested size is positive or that index+size stays within pool bounds, which could result in out-of-bounds access. While not inherently malicious, such patterns are dangerous and often associated with exploitation.

internal/rt/pool.go:12
medium

Potential integer overflow

NPS-3649AB8F81FC

The calculation uintptr(self.index)*AsGoType(self.typ).Size could overflow on 32-bit platforms or with large values, leading to pointer arithmetic underflow and out-of-bounds memory access.

internal/rt/pool.go:13
medium

Use of go:linkname to access runtime internals

NPS-39C062F81B08

The file uses //go:linkname directives extensively to access unexported runtime and reflect functions (runtime.memmove, runtime.mapiternext, runtime.mallocgc, reflect.makemap, runtime.throw, etc.). This bypasses Go's type safety and encapsulation guarantees, tightly coupling the package to specific Go runtime internals. This is characteristic of high-performance libraries (this appears to be ByteDance's sonic JSON library), but it is a fragile and potentially dangerous pattern: it can break with any Go version change, and similar techniques have been abused by malicious packages to manipulate memory, bypass security checks, or invoke privileged runtime behavior. It also complicates security auditing because the actual behavior depends on undocumented runtime internals.

internal/rt/stubs.go:22
medium

Extensive unsafe.Pointer arithmetic and raw memory manipulation

NPS-237AF3EEF5F8

The code performs direct memory operations via unsafe.Pointer (add, Memmove, MemclrHasPointers, MemclrNoHeapPointers, MakeSlice, GrowSlice) and type-puns slices via unsafe.Pointer(&emptyBytes). Such low-level manipulations can lead to memory corruption, use-after-free, or out-of-bounds access if misused. While consistent with the intended purpose of a runtime-reflection helper package, these primitives are the same ones that malicious code would leverage to tamper with process memory, bypass sandboxing, or execute arbitrary payloads. No actual exfiltration, credential harvesting, network activity, process spawning, or dynamic code execution is present, so the risk is limited to fragility and potential memory-safety hazards rather than direct malice.

internal/rt/stubs.go:150
medium

Potential incorrect bounds handling

NPS-B725ECB14004

The IntoBytes function checks capacity but not the length of the destination slice. It uses cap(*m) < len(s) as a guard, but then writes into the slice via unsafe pointer, bypassing slice length checks. This could lead to writing beyond the slice's logical length if the caller expects the length to be respected, potentially corrupting adjacent memory.

unquote/unquote.go:49
medium

Unsafe memory manipulation

NPS-D9D8D0C43A29

The code uses Go's unsafe package with pointer arithmetic to reinterpret slices and strings (rt.GoSlice, rt.GoString). While this is a known performance optimization technique in the sonic library, it bypasses Go's memory safety guarantees. If the native.Unquote function has a bug or is exploited, it could lead to memory corruption or arbitrary code execution.

unquote/unquote.go:60
low

build constraint complexity

NPS-5C9D1C40D1F5

Complex build tags restrict compilation to specific Go versions and architectures. This could be used to selectively include/exclude code across Go versions, though here it appears benign for compatibility.

ast/api.go:1
low

informational

NPS-F45B228B048A

The file contains a build tag that is intentionally never satisfied by normal Go toolchains (references go1.28 and contradictory constraints), ensuring this compatibility fallback is excluded from standard builds. No malicious behavior is present.

ast/api_compat.go:1
low

init function

NPS-DBC11906CDC4

An init() function is present that calls compat.Warn, which simply logs a warning about using the pure-Go fallback. This runs at import time but performs no dangerous operations.

ast/api_compat.go:29
low

Error handling bypass

NPS-7D957610AE42

In decodeValue, errors from decodeInt64 and decodeFloat64 are discarded (using _), and only the return code is checked. This could mask legitimate parsing errors, though it doesn't directly create a security vulnerability.

ast/decode.go:271
low

Build Constraint Compatibility

NPS-6D1E521559CB

This file is a compatibility fallback for non-optimized architectures. It uses standard library encoding/json instead of unsafe native assembly. No malicious behavior is present.

decoder/decoder_compat.go
low

init function warning

NPS-7DFD8F1A47FC

The init() function only calls compat.Warn('sonic/encoder'), which is a warning mechanism for using the fallback (compatibility) implementation on unsupported architectures. This is benign and does not perform any malicious activity.

encoder/encoder_compat.go:28
low

unsafe package usage

NPS-23ED5F987EE9

The code uses the unsafe package to manipulate pointers and directly access runtime internals via rt.UnpackEface and rt.Strhash. While this appears to be a legitimate performance optimization for string hashing (likely part of the Sonic JSON library), direct pointer manipulation bypasses Go's memory safety guarantees and could lead to memory corruption, crashes, or undefined behavior if the runtime internals change or if the function signature expectations are violated.

internal/caching/hashing.go:24
low

runtime internal access

NPS-04527F2FB673

The code accesses Go runtime internal functions (runtime.strhash) through the internal/rt package. This creates a tight coupling with specific Go runtime versions and may break on runtime updates. If the rt.Strhash signature or behavior differs across Go versions, the unsafe.Pointer cast could cause type confusion and memory safety issues.

internal/caching/hashing.go:27
low

init() function executes at import time

NPS-DC944F178395

Go init() runs at import time, but it only reads an env var and adjusts CPU feature flags; it performs no network, file, or process operations.

internal/cpu/features.go:34
low

Environment variable read

NPS-DEB13D87C669

The code reads the SONIC_MODE environment variable to optionally disable AVX2 CPU feature detection. This is a configuration mechanism, not credential harvesting, and does not exfiltrate any data.

internal/cpu/features.go:35
low

code generation and JIT-style optimization

NPS-973EC616A35A

This file is part of ByteDance's Sonic JSON library, which uses assembly and unsafe code for high-performance decoding. The pretouchImpl, pretouchManyImpl, and decodeImpl assignments reference optimization functions. This is a legitimate performance optimization pattern, not obfuscation or dynamic code execution. No eval/exec equivalents are used.

internal/decoder/api/decoder_arm64.go:25
low

init function execution

NPS-F443250915E6

The package defines an init() function that executes at import time, calling envs.EnableOptDec() and envs.EnableFastMap(). While init() functions are a common Go pattern, they do execute automatically when the package is imported. However, these calls only set internal package-level configuration flags (enabling decoder optimizations and fast map handling) with no external network, filesystem, or process activity. This is benign and consistent with the package's documented purpose.

internal/decoder/api/decoder_arm64.go:30
low

Import-time initialization (init functions)

NPS-69F7A846872D

Multiple init() functions execute at package load time, including setting up JIT function pointers (jit.Func), computing reflection types, and initializing float pointer values. While these do not perform I/O or network operations, they do initialize the JIT subsystem and cache function addresses. This is standard for this type of library but represents top-level code that runs on import.

internal/decoder/jitdec/assembler_regabi_amd64.go
low

Use of reflection and unsafe for type manipulation

NPS-C705F220FC32

The code uses reflect.TypeOf, rt.UnpackType, unsafe.Pointer, and direct manipulation of Go runtime type structures (rt.GoType, rt.GoItab). It accesses rt.F_kind_mask and _Gt_KindFlags via unsafe offset calculations. This relies on Go internal ABI details and could break or behave unexpectedly across Go versions. The build constraint (!go1.28) indicates awareness of version fragility.

internal/decoder/jitdec/assembler_regabi_amd64.go
low

Reflection-based compilation with raw type pointers

NPS-3BBE3510633D

The compiler uses rt.UnpackType and rt.GoType with unsafe.Pointer to bypass Go's type safety. Type metadata is stored as raw pointers in instructions (newInsVt, newInsVtI). If a type-confusion bug exists, this could be exploitable, but appears to be an internal, non-attacker-controlled path.

internal/decoder/jitdec/compiler.go:205
low

Compile-time code execution via Unmarshaler interfaces

NPS-5AA0439DB32F

The checkMarshaler function compiles calls into json.Unmarshaler, encoding.TextUnmarshaler interfaces at decode time via _OP_unmarshal/_OP_unmarshal_text opcodes. This is standard behavior for a JSON decoder, but it does mean that any type passed to this decoder can execute arbitrary user-defined code during unmarshaling.

internal/decoder/jitdec/compiler.go:487
low

Recover-based error handling

NPS-5B4B8CAB3A92

The rescue() function uses recover() to convert panics to errors. Recovered panics from attacker-influenced input could mask errors or cause unexpected states, though this is a common pattern and not indicative of malice.

internal/decoder/jitdec/compiler.go:517
low

Debug Environment Variables

NPS-7EEB5439CDDE

The code reads SONIC_SYNC_GC and SONIC_NO_ASYNC_GC environment variables to control debug garbage collection behavior. This is a standard debugging mechanism, not credential harvesting or exfiltration.

internal/decoder/jitdec/debug.go:20
low

Runtime Function Calls

NPS-D2C6BBCF36E3

Calls runtime.GC and debug.FreeOSMemory for garbage collection during debugging. These are legitimate Go runtime functions, not process spawning or shell commands.

internal/decoder/jitdec/debug.go:25
low

dynamic code generation / JIT assembly

NPS-E45C9EC0948D

This file implements a JIT (Just-In-Time) compiler that emits raw assembly instructions at runtime using the golang-asm library. While this is legitimate for a high-performance JSON decoder (sonic by ByteDance), dynamic code generation/execution is a red flag that warrants scrutiny. The generated machine code is executed directly via function pointers. This could theoretically be abused if the package were compromised to emit malicious instructions, but the current code appears to be a legitimate JSON decoder implementation.

internal/decoder/jitdec/generic_regabi_amd64.go
low

reflection and memory manipulation

NPS-E0940B8BB0B6

Uses reflect.TypeOf and unsafe-style pointer operations (jit.Ptr, WriteRecNotAX, WritePtrAX) to write directly to Go runtime memory structures like interfaces and slices. This is standard for a high-performance JSON decoder but constitutes memory manipulation that could be dangerous if the code were modified maliciously.

internal/decoder/jitdec/generic_regabi_amd64.go
low

runtime library calls via assembly

NPS-8F11B9D14208

The code calls internal Go runtime functions (runtime.makeslice, runtime.convTslice, runtime.convTstring, runtime.mapassign_faststr, runtime.growslice, runtime.mallocgc) directly via JIT-emitted CALL instructions. These are normal for this type of optimized decoder but bypass normal Go function call safety.

internal/decoder/jitdec/generic_regabi_amd64.go
low

Direct memory allocation

NPS-6CF65962B961

ptrDecoder.FromDom and embeddedFieldPtrDecoder.FromDom call rt.Mallocgc directly to allocate memory for pointer targets. While unusual in typical Go code, this is consistent with the library's low-level performance-oriented design and not evidence of malicious behavior.

internal/decoder/optdec/functor.go:25
low

no input size/complexity limits

NPS-DEB76278D75B

The decoders iterate over obj.Len() (the parsed JSON object length) without any explicit bound on map size or loop count, and they allocate maps using rt.Makemap with obj.Len() as the size hint. A maliciously large JSON object could cause excessive memory allocation (memory exhaustion DoS). No MAX_MAP_SIZE or similar guard is present in this file.

internal/decoder/optdec/map.go
low

global mutable state and sync.Pool reuse

NPS-4A04BFB37553

A sync.Pool of Parser objects is shared globally, and reset() reinitializes fields but does not clear the underlying 'dbuf' or fully zero the reused node slices. Residual data from previous parses could persist in memory and, in combination with unsafe pointer reuse, might leak data between logically separate parsing operations.

internal/decoder/optdec/native.go:124
low

no explicit malicious behavior

NPS-7516356D3DE0

No network calls, file system access outside package scope, process spawning, environment variable harvesting, obfuscated payloads, dynamic code execution, cryptocurrency mining, or backdoor installation were found. The code appears to be a performance-oriented JSON decoder.

internal/decoder/optdec/node.go
low

Potential unsafe memory clearing

NPS-15278E696F0B

In arrayDecoder.FromDom, the code uses rt.ClearMemory with a computed pointer and size to zero out the remaining elements of an array. The comment acknowledges that the boundary pointer may point to an unknown object, and the call is guarded by if n != 0. However, if d.len and d.elemType.Size are not consistent with the actual array length, this could clear unintended memory, leading to data corruption or crashes. This is a correctness/safety concern rather than an obvious backdoor, but it reinforces the need for strict validation of type parameters.

internal/decoder/optdec/slice.go
low

Dynamic code generation/JIT compilation

NPS-244308114E42

This file implements a JIT (Just-In-Time) compiler that generates and executes machine code at runtime using the x86 assembler and loader packages. While this is legitimate functionality for the ByteDance Sonic JSON library to achieve high performance, dynamic code generation is an advanced technique that could potentially be abused if the library were compromised. The code uses unsafe pointers and assembles native instructions at runtime.

internal/encoder/pools_amd64.go
low

Use of unsafe package

NPS-DD690C3705A3

The code imports and uses the 'unsafe' package extensively (e.g., unsafe.Pointer in _KeepAlive struct). This bypasses Go's type safety guarantees. In this context it's used for JIT-compiled function pointer management and is consistent with the library's high-performance design, but represents elevated risk surface.

internal/encoder/pools_amd64.go:21
low

Init-time behavior

NPS-4508CBB6E43D

The init() function runs automatically at package import time. It configures the encoder to use JIT compilation by default. This executes code (compiler setup) at import time, though no network, filesystem, or process manipulation occurs.

internal/encoder/pools_amd64.go:38
low

Import-time initialization

NPS-BFE59F7D57B1

The file contains an init() function that calls ForceUseVM(). This runs at import time. However, the call is to a local package function (github.com/bytedance/sonic/option) and only configures encoder behavior for non-amd64 platforms; there is no evidence of malicious activity, network access, file system access, or dynamic code execution.

internal/encoder/pools_compt.go:29
low

Environment variable access

NPS-200F17373DCE

The code reads environment variables (SONIC_SYNC_GC, SONIC_NO_ASYNC_GC, SONIC_CHECK_POINTER, SONIC_ENCODER_USE_VM) to configure debug and runtime behavior. These are not credential-harvesting patterns; they are configuration toggles for the package's own operation.

internal/encoder/vars/const.go
low

Use of unsafe package

NPS-EB6C1ED325C3

The unsafe package is used only to compute memory sizes of structs (Stack and State) at compile time. No pointer manipulation or memory-unsafe operations are performed.

internal/encoder/vars/const.go
low

Unsafe pointer usage

NPS-26CBB2DEC252

Uses unsafe.Pointer and casts to *rt.GoString for formatting. This is standard low-level trickery in the sonic library for performance and is not malicious, but misuse can cause memory corruption or crashes if inputs are not well-formed.

internal/encoder/vars/errors.go:94
low

Panic with data inclusion

NPS-904C34CA3B22

GoPanic deliberately panics with up to maxJSONLength bytes of the JSON buffer embedded in the panic string. If this buffer contains sensitive data (credentials, tokens, PII) and panic output is logged or reported to an error tracking service, that data could be leaked. This is a defensive design choice to aid debugging, not exfiltration, but it has a data-disclosure risk.

internal/encoder/vars/errors.go:101
low

Environment variable configuration

NPS-849E5B5D8D59

The init() function reads the SONIC_PANIC_MAX_JSON_LENGTH environment variable to configure the maximum JSON length included in panic messages. While this is a legitimate configuration mechanism used by the sonic JSON library, init() functions run automatically at import time and environment-driven behavior can be surprising. The value is validated with strconv.Atoi and only applied if parsing succeeds.

internal/encoder/vars/errors.go:119
low

Type-unsafe Pool usage

NPS-66386B8EF5AB

bytesPool, stackPool, and bufferPool are plain sync.Pool without type guarantees. NewBytes/NewBuffer/NewStack use unchecked type assertions. While in normal operation the pools only hold their intended types, sharing a package-level pool means any code with access to the package could inject a different type and cause a panic on assertion.

internal/encoder/vars/stack.go

Files reviewed

FileVerdictWhat the reviewer saw
ast/api.go medium The code uses unsafe pointers and native assembly calls typical of a high-performance JSON library, but these patterns reduce auditability and could conceal vulnerabilities; no direct malicious intent is evident.
ast/decode.go medium This is a legitimate JSON parsing library from ByteDance's sonic project using unsafe pointer arithmetic for performance; no malicious patterns detected, but unsafe memory operations warrant caution.
ast/error.go medium The code contains unsafe pointer usage that creates dangling pointers to local stack variables, leading to potential memory corruption and undefined behavior.
ast/stubs.go medium The code uses unsafe package for slice-to-pointer conversion, a legitimate but potentially dangerous pattern that warrants review, though no active malicious behavior is present.
internal/caching/hashing.go medium The code uses unsafe pointer manipulation and Go runtime internals for string hashing performance, which is risky but appears legitimate for the Sonic JSON library with no evidence of malicious intent.
internal/decoder/jitdec/assembler_regabi_amd64.go medium This is a legitimate JIT compiler backend for the ByteDance sonic JSON library that generates native x86-64 code at runtime; while it uses high-risk techniques (runtime code generation, unsafe pointer manipulation, direct machine code emission), no malicious patterns such as data exfiltration, credential harvesting, network calls, or backdoor installation were detected.
internal/decoder/jitdec/compiler.go medium This is ByteDance's sonic JIT JSON decoder compiler; it contains no network, filesystem, process spawning, environment/credential access, obfuscation, or install-time execution patterns, but it does pervasively use unsafe pointer manipulation and reflection-based type handling which are inherent risks of the JIT design rather than evidence of malicious intent.
internal/decoder/jitdec/generic_regabi_amd64.go medium This is a legitimate JIT-based JSON decoder from the ByteDance sonic package; it uses dynamic assembly generation and runtime memory manipulation, which are unusual but expected for high-performance decoders, with no evidence of data exfiltration, credential harvesting, or backdoor behavior.
internal/decoder/optdec/functor.go medium Code is a legitimate portion of the sonic JSON decoding library using unsafe pointer arithmetic for performance; no exfiltration, credential harvesting, obfuscation, or malicious behavior is present.
internal/decoder/optdec/map.go medium The file is a legitimate JSON-to-map decoder from the ByteDance sonic library, but it relies heavily on unsafe pointers, runtime internals, and a lack of input-size limits, which are robustness/safety concerns rather than malicious patterns.
internal/decoder/optdec/native.go medium This is a legitimate high-performance JSON parser using unsafe memory operations and a native library, but it exhibits memory-safety and resource-exhaustion risks typical of such code rather than outright malicious behavior.
internal/decoder/optdec/node.go medium The code is a high-performance JSON parser using extensive unsafe pointer arithmetic and manual memory management, which presents memory safety risks but shows no overt malicious intent such as data exfiltration or backdoor installation.
internal/decoder/optdec/slice.go medium The code is a performance-oriented JSON decoder using unsafe pointer arithmetic and manual memory management; no clear malicious patterns, but the heavy reliance on unsafe operations and disabled pointer checks pose a potential security risk if not carefully validated.
internal/encoder/pools_amd64.go medium This is a legitimate JIT compiler module from the ByteDance Sonic JSON library; it uses advanced techniques (unsafe, dynamic machine code generation) that warrant caution but show no evidence of malicious behavior such as exfiltration, credential harvesting, or backdoors.
internal/encoder/vars/errors.go medium The file is part of ByteDance's sonic JSON library and contains only legitimate error-handling and panic-formatting logic; the only concerns are a benign import-time environment variable read and inclusion of a bounded amount of caller-provided JSON in panic messages.
internal/encoder/vars/stack.go medium No overtly malicious behavior found, but the file relies heavily on unsafe pointer arithmetic and type-unsafe sync.Pool usage, which carries memory-safety risk if invariants (StackSize, MaxStack, pool contents) are violated.
internal/encoder/x86/debug_go117.go medium The file contains unsafe pointer operations and runtime linkname hacks typical of a debugging JIT assembler, but no clear malicious intent such as exfiltration, backdoors, or process spawning was found.
internal/jit/assembler_amd64.go medium This is a JIT assembler for the Sonic JSON library that generates and executes machine code at runtime; while it appears to be a legitimate performance component, the dynamic code generation and import-time execution patterns carry inherent risk if the package is compromised or if inputs are not strictly controlled.
internal/jit/backend.go medium This is a legitimate JIT backend for the ByteDance sonic library; it dynamically generates x86 machine code, which is inherently sensitive, but no exfiltration, credential harvesting, obfuscation, or backdoor patterns were found.
internal/jit/runtime.go medium The file is part of a legitimate JIT compiler (sonic) but uses unsafe pointer arithmetic and runtime type introspection typical of code-generation engines, which warrants a warning rather than a safe classification.
internal/native/avx2/f64toa.go medium This appears to be a legitimate generated AVX2 assembly bridge for the sonic JSON library; no direct malicious patterns are present, though the unsafe indirect native call warrants review of its assembly implementation.
internal/native/avx2/i64toa.go medium The code uses unsafe pointers and external function pointers for performance optimization, which is typical for SIMD assembly integration but carries inherent memory safety risks; no direct malicious behavior is evident.
internal/native/avx2/quote.go medium The code appears to be a legitimate generated wrapper for an AVX2-optimized JSON quoting function from the ByteDance sonic library, using unsafe pointers for performance, but no clear malicious patterns were detected.
internal/native/avx2/validate_utf8_fast.go medium No overt malicious intent detected, but the code relies on unsafe memory operations and external function pointers, posing moderate safety and maintainability risks.
internal/native/avx2/value.go medium The code is a legitimate part of a performance-oriented JSON library using unsafe pointers and AVX2 assembly, which is a low-risk pattern but warrants caution due to unsafe native interface usage.
Show 265 more files
FileVerdictWhat the reviewer saw
internal/native/dispatch_arm64.go medium The code uses unsafe pointers and linkname directives for performance-critical JSON parsing, but no malicious patterns such as data exfiltration, credential harvesting, or backdoors were detected.
internal/native/sse/f64toa.go medium The file is a low-level, generated Go wrapper around an assembly implementation for float-to-ASCII conversion; it uses unsafe pointers and external function pointers but contains no direct malicious patterns such as data exfiltration, credential harvesting, or dynamic code execution.
internal/native/sse/html_escape.go medium The file is a generated, low-level unsafe/FFI binding for an HTML escape routine; no malicious patterns are present, though its use of unsafe pointers and a mutable function-pointer indirection is worth noting as a minor attack-surface concern.
internal/native/sse/i64toa.go medium The code uses unsafe pointers and native function pointers for performance, which poses a moderate security risk but shows no clear malicious intent.
internal/native/sse/native_export.go medium The file safely wires Go to bundled native C implementations via loader.WrapGoC, but the native binding pattern and potential import-time activation represent a moderate trust-boundary risk that depends on the integrity of the referenced C source files.
internal/native/sse/parse_with_padding.go medium The file uses unsafe pointers and external function pointer assignment typical of performance-optimized native bindings, but lacks direct malicious patterns; risk is limited to unaudited native code dependency.
internal/native/sse/skip_number.go medium The code is a generated assembly stub using unsafe pointers for performance, with no active malicious patterns, but the reliance on external function pointers warrants low-level caution.
internal/native/sse/skip_one_fast.go medium The code uses unsafe pointers and a native function call for performance, which poses a moderate risk if the native implementation is malicious or memory corruption occurs, but no direct malicious patterns are present.
internal/native/sse/validate_utf8_fast.go medium The file is a generated unsafe/FFI shim for a native UTF-8 validator; it shows no overt malicious behavior but its reliance on unsafe pointers and externally resolved symbols reduces auditability.
internal/native/sse/vnumber.go medium The file uses unsafe pointers and an externally-injected function pointer, a typical native-binding pattern for the Sonic JSON library, with no direct evidence of malicious behavior in this snippet.
internal/native/sse/vstring.go medium The file contains unsafe pointer manipulation and native function bindings typical of performance-focused JSON parsing, posing medium risk if the native implementation is not securely resolved.
internal/rt/base64_amd64.go medium The code uses unsafe linkname to access internal symbols of a third-party base64 library, introducing encapsulation bypass and supply chain risks, though no direct malicious behavior is present.
internal/rt/fastconv.go medium The code uses unsafe pointer arithmetic and internal runtime types to manipulate memory, which poses a medium risk of memory corruption or undefined behavior, but no direct malicious patterns such as data exfiltration, credential harvesting, or backdoors were found.
internal/rt/fastvalue.go medium The code uses unsafe pointer arithmetic and runtime internals for reflection, which is typical for high-performance libraries but carries memory safety risks; no direct malicious behavior such as exfiltration, credential harvesting, or backdoors was found.
internal/rt/gcwb.go medium The code uses unsafe, linkname, and runtime disassembly to access and compute addresses of internal Go runtime structures, which is a security concern due to bypassing safety mechanisms and potential for runtime manipulation.
internal/rt/gcwb_legacy.go medium Code uses go:linkname to access unexported Go runtime internals, which is an unsafe but likely legitimate GC write-barrier implementation; no exfiltration, credential harvesting, or malicious behavior observed.
internal/rt/growslice.go medium The file uses legitimate but risky low-level Go runtime hacks (unsafe, go:linkname, memory layout assumptions) that carry memory-safety risks if runtime internals change, but no malicious patterns such as exfiltration, backdoors, or command execution were detected.
internal/rt/growslice_legacy.go medium The file contains an unsafe //go:linkname binding to runtime.growslice, a legitimate but risky pattern typical of ByteDance's sonic library; no malicious behavior was detected, but linkname usage warrants caution and cross-checking with sibling build-tag variants.
internal/rt/pool.go medium The code uses unsafe pointer arithmetic without sufficient bounds checking, which could lead to memory safety issues, but no overtly malicious behavior is present.
internal/rt/stubs.go medium The file contains no exfiltration, credential harvesting, network, process, or obfuscation indicators, but its heavy use of go:linkname and unsafe.Pointer runtime internals is a fragile, high-privilege pattern that warrants caution when auditing or trusting the package.
unquote/unquote.go medium The code uses unsafe memory operations for performance, which introduces memory safety risks but appears to be part of a legitimate JSON library (sonic) rather than malicious activity.
api.go safe Cleared by Jev triage; no further analysis needed
ast/api_compat.go safe This compatibility fallback file contains only benign JSON parsing helpers and a warning logger; no malicious patterns were detected.
ast/buffer.go safe No malicious patterns detected; the code implements data structure utilities with no network, filesystem, process, or obfuscated behavior.
ast/encode.go safe No malicious patterns detected
ast/iterator.go safe Cleared by Jev triage; no further analysis needed
ast/node.go safe No malicious patterns detected; the code is a legitimate JSON AST node implementation from ByteDance's sonic library with only safe operations (memory manipulation, parsing, serialization, no external I/O, exec, or network calls).
ast/parser.go safe No malicious patterns detected; the code is a legitimate JSON parser from the ByteDance Sonic library with no data exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
ast/search.go safe No malicious patterns detected; the code is a legitimate JSON AST search utility from the ByteDance Sonic library with no network, filesystem, process execution, or obfuscated behavior.
ast/visitor.go safe Cleared by Jev triage; no further analysis needed
compat.go safe Cleared by Jev triage; no further analysis needed
decoder/decoder_compat.go safe No malicious patterns detected; this is a legitimate compatibility shim for the sonic JSON library.
decoder/decoder_native.go safe Cleared by Jev triage; no further analysis needed
encoder/encoder_compat.go safe The code is a safe fallback/compatibility implementation of a JSON encoder using standard library functions; no malicious patterns were detected.
encoder/encoder_native.go safe Cleared by Jev triage; no further analysis needed
internal/caching/fcache.go safe No malicious patterns detected; code is a legitimate hash map implementation for caching field lookups with no suspicious behavior.
internal/caching/pcache.go safe No malicious patterns detected; the code implements a legitimate concurrent hash map cache for serialization programs with no network, filesystem, process, or obfuscation concerns.
internal/compat/warn.go safe Cleared by Jev triage; no further analysis needed
internal/cpu/features.go safe The file is a benign CPU feature detection helper that optionally disables AVX2 via an environment variable, with no malicious behavior.
internal/decoder/api/decoder.go safe No malicious patterns detected; this is a legitimate JSON decoder from the ByteDance sonic library with only standard decoding functionality.
internal/decoder/api/decoder_amd64.go safe No malicious patterns detected; the file only selects JIT or opt decoder implementations based on build tags and an environment variable.
internal/decoder/api/decoder_arm64.go safe The file is part of ByteDance's Sonic JSON library and contains only benign architecture-specific initialization that enables internal decoder optimizations without any malicious behavior.
internal/decoder/api/stream.go safe No malicious patterns detected; the code implements a standard streaming JSON decoder with buffer pooling and no external network, file system, or process activity.
internal/decoder/consts/option.go safe Cleared by Jev triage; no further analysis needed
internal/decoder/errors/errors.go safe Cleared by Jev triage; no further analysis needed
internal/decoder/jitdec/asm_stubs_amd64_go117.go safe This file contains low-level JIT assembly helper functions for garbage collector write barriers in the Sonic JSON library; no malicious patterns such as data exfiltration, credential harvesting, dynamic code execution, or network activity were detected.
internal/decoder/jitdec/asm_stubs_amd64_go121.go safe No malicious patterns detected
internal/decoder/jitdec/debug.go safe Debug utilities using environment variables and runtime GC calls for internal debugging; no malicious patterns detected.
internal/decoder/jitdec/decoder.go safe The code is a legitimate JSON decoder from the Sonic library using unsafe pointer operations and runtime code generation, with no evidence of malicious patterns such as data exfiltration, credential harvesting, or backdoor installation.
internal/decoder/jitdec/pools.go safe No malicious patterns detected; the file is a legitimate memory pool and caching implementation for the ByteDance Sonic JSON decoder using unsafe pointer operations typical of high-performance Go code.
internal/decoder/jitdec/primitives.go safe No malicious patterns detected; the code is a legitimate part of the Sonic JSON decoder using unsafe pointers and JIT compilation, with no exfiltration, credential harvesting, obfuscation, or other red flags.
internal/decoder/jitdec/types.go safe No malicious patterns detected; the file only declares reflection type variables and a helper that converts reflect.Type to internal Go runtime type representations, all consistent with legitimate JSON decoder implementation in the Sonic library.
internal/decoder/jitdec/utils.go safe No malicious patterns detected; the file contains low-level unsafe pointer helpers and an assertion utility typical of a JIT decoder implementation with no network, filesystem, process, or obfuscation behavior.
internal/decoder/optdec/compile_struct.go safe Cleared by Jev triage; no further analysis needed
internal/decoder/optdec/compiler.go safe No malicious patterns detected
internal/decoder/optdec/const.go safe Cleared by Jev triage; no further analysis needed
internal/decoder/optdec/context.go safe Cleared by Jev triage; no further analysis needed
internal/decoder/optdec/decoder.go safe No malicious patterns detected; the code is a standard JSON decoder with no exfiltration, credential harvesting, obfuscation, or process execution.
internal/decoder/optdec/errors.go safe Cleared by Jev triage; no further analysis needed
internal/decoder/optdec/helper.go safe Cleared by Jev triage; no further analysis needed
internal/decoder/optdec/interface.go safe No malicious patterns detected; the code is a legitimate JSON decoder implementation using unsafe for performance optimization, with no network, filesystem, process, or obfuscation concerns.
internal/decoder/optdec/stringopts.go safe No malicious patterns detected; the code implements JSON string-to-primitive decoders using unsafe pointers and reflection helpers consistent with the bytedance/sonic library's internal operations.
internal/decoder/optdec/structs.go safe No malicious patterns detected; the code is a standard JSON struct decoder using reflection and unsafe pointers for performance, with no exfiltration, obfuscation, or suspicious behavior.
internal/decoder/optdec/types.go safe No malicious patterns detected; the file only contains standard reflect type definitions and unsafe pointer conversions for JSON decoding.
internal/encoder/alg/mapiter.go safe No malicious patterns detected; this is a legitimate Go JSON encoder map iterator with standard unsafe/reflection usage but no exfiltration, code execution, or backdoor mechanisms.
internal/encoder/alg/opts.go safe Cleared by Jev triage; no further analysis needed
internal/encoder/alg/sort.go safe Cleared by Jev triage; no further analysis needed
internal/encoder/alg/spec.go safe No malicious patterns detected; the code is a legitimate performance-optimized JSON encoder with unsafe operations for speed, but no security concerns like data exfiltration, backdoors, or code execution.
internal/encoder/alg/spec_compat.go safe The Go file contains standard JSON encoding utilities with no suspicious network, filesystem, process execution, or obfuscated behavior.
internal/encoder/compiler.go safe The code is a JSON encoder compiler from the Sonic library and contains no malicious patterns.
internal/encoder/encode_norace.go safe Cleared by Jev triage; no further analysis needed
internal/encoder/encode_race.go safe Cleared by Jev triage; no further analysis needed
internal/encoder/encoder.go safe No malicious patterns detected in the analyzed Go encoder source file.
internal/encoder/ir/op.go safe No malicious patterns detected; the code is a legitimate part of the Sonic JSON encoder/decoder library implementing instruction set operations with no exfiltration, obfuscation, or dynamic execution.
internal/encoder/pools_compt.go safe No malicious patterns detected; the only import-time code is a benign local configuration call for non-amd64 builds.
internal/encoder/prim/primitives.go safe No malicious patterns detected; the code is a legitimate JSON encoding helper from ByteDance's Sonic library with only standard unsafe/reflect usage for performance.
internal/encoder/stream.go safe Cleared by Jev triage; no further analysis needed
internal/encoder/vars/cache.go safe No malicious patterns detected; the file contains a straightforward program cache for a JSON encoder library.
internal/encoder/vars/const.go safe The file only defines constants and reads environment variables for configuration; no malicious patterns such as exfiltration, credential harvesting, obfuscation, or backdoor behavior were detected.
internal/encoder/vars/types.go safe Cleared by Jev triage; no further analysis needed
internal/encoder/vm/stbus.go safe No malicious patterns detected; the code is a legitimate part of the Sonic JSON encoder with no signs of data exfiltration, credential harvesting, or other security concerns.
internal/encoder/vm/vm.go safe No malicious patterns detected
internal/encoder/x86/asm_stubs_amd64_go117.go safe The code is a low-level Go assembler stub for write barriers and does not contain any malicious patterns; it is a legitimate part of the Sonic JSON library.
internal/encoder/x86/asm_stubs_amd64_go121.go safe The file contains low-level x86 assembly stubs for Go runtime write barriers and exhibits no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or unauthorized code execution.
internal/encoder/x86/assembler_export_amd64.go safe No malicious patterns detected; the code is a simple build-constrained export wrapper for an assembler.
internal/encoder/x86/assembler_regabi_amd64.go safe The file is a legitimate JIT assembler for the Sonic JSON encoder; no malicious patterns were detected.
internal/encoder/x86/debug_go116.go safe No malicious patterns detected; the code is a legitimate Go debug helper for JIT assembler with GC triggering controlled by environment variables, all functions are internal and standard library based.
internal/encoder/x86/stbus.go safe No malicious patterns detected; the code is a legitimate low-level encoder utility from the Sonic JSON library using standard Go unsafe operations.
internal/envs/decode.go safe No malicious patterns detected; the code only reads two environment variables and provides toggle functions for internal flags.
internal/jit/arch_amd64.go safe No malicious patterns detected; the code is a benign JIT architecture helper for AMD64 with no network, file, process, or obfuscation activity.
internal/native/avx2/f32toa.go safe This file contains only a safe, generated wrapper around a SIMD-accelerated float-to-ASCII conversion function with no malicious patterns.
internal/native/avx2/f32toa_subr.go safe This is a generated assembly metadata file for an AVX2 f32-to-ASCII conversion function in the bytedance/sonic library, containing only PC/SP tables and loader.CFunc definitions with no malicious patterns.
internal/native/avx2/f32toa_text_amd64.go safe No malicious patterns detected; the file contains auto-generated AMD64 assembly bytes for a float-to-ASCII conversion routine, with no network, filesystem, process, or dynamic code execution behavior.
internal/native/avx2/f64toa_subr.go safe No malicious patterns detected; the file is a generated assembly metadata declaration for the bytedance/sonic AVX2 f64toa routine with no executable or suspicious logic.
internal/native/avx2/get_by_path.go safe No malicious patterns detected; the file is a generated FFI wrapper for AVX2-accelerated JSON path lookup with only unsafe.Pointer conversions and no suspicious behavior.
internal/native/avx2/get_by_path_subr.go safe Auto-generated assembly metadata for an AVX2 native function; contains no malicious patterns.
internal/native/avx2/html_escape.go safe No malicious patterns detected; the file is a generated AVX2 assembly wrapper for HTML escaping with only unsafe pointer usage for performance and no network, file, credential, process, or obfuscated behavior.
internal/native/avx2/html_escape_subr.go safe The file contains only static metadata and function registration for an AVX2 assembly routine; no malicious patterns, dynamic execution, network activity, or filesystem access were detected.
internal/native/avx2/html_escape_text_amd64.go safe No malicious patterns detected
internal/native/avx2/i64toa_subr.go safe This is an autogenerated Go assembly wrapper for bytedance/sonic's AVX2 i64toa function containing only static metadata and no malicious patterns.
internal/native/avx2/i64toa_text_amd64.go safe This is an auto-generated Go assembly file implementing AVX2-accelerated integer-to-ASCII conversion with no network, filesystem, process, or dynamic code execution capabilities.
internal/native/avx2/lspace.go safe No malicious patterns detected; the file defines a low-level unsafe-pointer function binding for AVX2 lspace with no network, file, process, or dynamic execution behavior.
internal/native/avx2/lspace_subr.go safe No malicious patterns detected; the file is a generated assembly metadata stub for an AVX2 function within the bytedance/sonic library.
internal/native/avx2/lspace_text_amd64.go safe This file contains generated AVX2 assembly bytecode for an lspace (left-space/whitespace skipping) function, with no network, filesystem, process, credential, or code-execution behavior.
internal/native/avx2/native_export.go safe No malicious patterns detected; the file contains only JIT function registration for a known performance library (sonic AVX2).
internal/native/avx2/parse_with_padding.go safe No malicious patterns detected; the file is a generated, legitimate wrapper for a native AVX2 JSON parsing function from the Sonic library with no external calls, file access, or obfuscation.
internal/native/avx2/parse_with_padding_subr.go safe This is a generated Go assembly-wrapper file for an AVX2 JSON parser with only static function metadata and no malicious patterns.
internal/native/avx2/quote_subr.go safe This is an auto-generated Go assembly metadata file for the Sonic JSON library's AVX2 quote function; it contains only static tables of PC/SP offsets and function descriptors with no executable logic, I/O, network calls, or other malicious patterns.
internal/native/avx2/skip_array.go safe No malicious patterns detected
internal/native/avx2/skip_array_subr.go safe Generated AVX2 assembly wrapper for JSON skip_array with no imports beyond a local loader package and no malicious patterns.
internal/native/avx2/skip_number.go safe No malicious patterns detected
internal/native/avx2/skip_number_subr.go safe No malicious patterns detected; this is a generated assembly support file for the sonic JSON library containing only metadata tables for a native skip_number function.
internal/native/avx2/skip_number_text_amd64.go safe This is a generated AVX2 assembly byte array for a UTF-8 number-skipping routine with no network, filesystem, process, or dynamic code execution activity.
internal/native/avx2/skip_object.go safe No malicious patterns detected; the file is a generated Go wrapper around an AVX2 skip_object function using unsafe pointers for performance, with no network, filesystem, process execution, or credential access.
internal/native/avx2/skip_object_subr.go safe No malicious patterns detected
internal/native/avx2/skip_one.go safe This is a generated Go file from the ByteDance Sonic JSON library that provides a thin wrapper around an AVX2 assembly function using unsafe pointers; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process execution were detected.
internal/native/avx2/skip_one_fast.go safe No malicious patterns detected; the file only declares an assembly-backed function pointer used by the sonic JSON library for AVX2 acceleration, with no network, filesystem, process, credential, or obfuscation behavior.
internal/native/avx2/skip_one_fast_subr.go safe No malicious patterns detected; the file contains only generated assembly metadata and loader registration for AVX2 optimized JSON parsing.
internal/native/avx2/skip_one_fast_text_amd64.go safe No malicious patterns detected; the file contains only machine-generated AVX2 assembly bytecode for a JSON skip-one-fast function with no network, filesystem, process, credential, or dynamic execution activity.
internal/native/avx2/skip_one_subr.go safe No malicious patterns detected in the analyzed Go assembly-metadata file; it only declares constants and a loader.CFunc table for a statically linked AVX2 routine.
internal/native/avx2/u64toa.go safe No malicious patterns detected; the file only provides a thin unsafe wrapper around a function pointer for uint64-to-ASCII conversion.
internal/native/avx2/u64toa_subr.go safe This is a generated assembly metadata file for the Sonic JSON library's u64toa function with no malicious patterns.
internal/native/avx2/u64toa_text_amd64.go safe This is a machine-generated assembly bytecode file for optimized integer-to-string conversion with no malicious patterns, network activity, filesystem access, or code execution beyond its intended purpose.
internal/native/avx2/unquote.go safe No malicious patterns detected
internal/native/avx2/unquote_subr.go safe No malicious patterns detected; the file only contains generated metadata for an assembly function registration.
internal/native/avx2/unquote_text_amd64.go safe No malicious patterns detected; this is a generated assembly byte slice implementing JSON string unquoting in the AVX2 assembly routine.
internal/native/avx2/validate_one.go safe No malicious patterns detected; the file contains only a generated Go binding to a native AVX2 validation function within the ByteDance Sonic JSON library.
internal/native/avx2/validate_one_subr.go safe This is a generated assembly metadata file for an AVX2-optimized JSON validation routine in the Sonic library, containing only static stack/PC mapping tables and loader function descriptors with no network, filesystem, process, or dynamic execution behavior.
internal/native/avx2/validate_utf8.go safe No malicious patterns detected; the file contains generated Go bindings for AVX2 UTF-8 validation without external network, filesystem, process, or code-execution activity.
internal/native/avx2/validate_utf8_fast_subr.go safe No malicious patterns detected; the file contains generated AVX2 assembly metadata and function registration for UTF-8 validation with no suspicious behavior.
internal/native/avx2/validate_utf8_fast_text_amd64.go safe No malicious patterns detected; the file contains only generated assembly data for an AVX2 UTF-8 validation routine with no network, filesystem, process, or dynamic execution behavior.
internal/native/avx2/validate_utf8_subr.go safe This is a generated Go assembly metadata file for UTF-8 validation using AVX2, containing only loader function descriptors and stack frame metadata with no malicious patterns.
internal/native/avx2/validate_utf8_text_amd64.go safe No malicious patterns detected; this file contains only generated x86-64 assembly bytes for a UTF-8 validation routine.
internal/native/avx2/value_subr.go safe No malicious patterns detected; the file contains only generated assembly metadata and loader configuration for an AVX2-optimized value parser.
internal/native/avx2/vnumber.go safe No malicious patterns detected; the file contains only Go bindings for AVX2 assembly routines without network, filesystem, or process manipulation.
internal/native/avx2/vnumber_subr.go safe No malicious patterns detected in this generated Go assembly metadata file; it only defines function entry sizes, stack sizes, and PCSP mappings for an AVX2 native function.
internal/native/avx2/vsigned.go safe No malicious patterns detected; the code is a legitimate unsafe pointer wrapper for AVX2 native JSON parsing with no network, file, process, or dynamic execution behavior.
internal/native/avx2/vsigned_subr.go safe No malicious patterns detected; this is a generated assembly loader file from the sonic project defining metadata for a signed comparison routine, containing no executable logic, network activity, or suspicious behavior.
internal/native/avx2/vsigned_text_amd64.go safe No malicious patterns detected; this is a generated assembly byte slice for an AVX2-accelerated signed integer parsing routine with no network, filesystem, process, or dynamic code execution behavior.
internal/native/avx2/vstring.go safe No malicious patterns detected; the file is a legitimate low-level wrapper for calling an assembly-implemented JSON string function using unsafe pointers and does not perform any exfiltration, credential harvesting, code execution, or other suspicious activity.
internal/native/avx2/vstring_subr.go safe No malicious patterns detected; this is a generated Go assembly wrapper file defining metadata tables for a native AVX2 string function.
internal/native/avx2/vstring_text_amd64.go safe This is a machine-generated AVX2 assembly bytecode blob for JSON string scanning (looking for quotes, backslashes, and control characters) with no malicious patterns detected.
internal/native/avx2/vunsigned.go safe No malicious patterns detected; the file is a thin Go wrapper around a native AVX2 function using unsafe pointers for JSON parsing, a standard pattern in the sonic library.
internal/native/avx2/vunsigned_subr.go safe No malicious patterns detected; this is a generated assembly wrapper for AVX2 SIMD code with no executable logic or suspicious behavior.
internal/native/avx2/vunsigned_text_amd64.go safe This is a generated assembly implementation of an unsigned integer parsing routine for a JSON package, with no malicious patterns detected.
internal/native/dispatch_amd64.go safe No malicious patterns detected; the file contains legitimate CPU dispatch logic for selecting optimized JSON parsing implementations (AVX2/SSE) in the ByteDance sonic library.
internal/native/neon/f32toa_arm64.go safe No malicious patterns detected
internal/native/neon/f32toa_subr_arm64.go safe No malicious patterns detected in the generated Go assembly stub, which only declares a stack size, a function entry pointer, and compile-time no-op variable references.
internal/native/neon/f64toa_arm64.go safe No malicious patterns detected
internal/native/neon/f64toa_subr_arm64.go safe This file is a machine-generated assembly binding stub for an ARM64 float-to-ASCII conversion routine with no executable logic, network, filesystem, or process-spawning behavior.
internal/native/neon/get_by_path_arm64.go safe The file contains only a simple wrapper function for a native assembly implementation of get_by_path, with no network, filesystem, process, or obfuscated code patterns.
internal/native/neon/get_by_path_subr_arm64.go safe Generated assembly stub file contains only a symbol declaration and stack size constants with no executable logic or malicious patterns.
internal/native/neon/html_escape_arm64.go safe No malicious patterns detected
internal/native/neon/html_escape_subr_arm64.go safe Generated assembly stub file with no executable logic, only a function declaration and constant definitions; no malicious patterns detected
internal/native/neon/i64toa_arm64.go safe No malicious patterns detected
internal/native/neon/i64toa_subr_arm64.go safe No malicious patterns detected; this is a generated assembly bridge for i64toa with only symbol declarations and no executable logic.
internal/native/neon/lspace_arm64.go safe No malicious patterns detected; the file contains only a Go assembly function declaration for JSON whitespace skipping from the bytedance/sonic library.
internal/native/neon/lspace_subr_arm64.go safe No malicious patterns detected in this generated ARM64 NEON assembly entry stub; it only declares a nosplit/noescape function pointer and stack size constants with no network, filesystem, exec, or obfuscation behavior.
internal/native/neon/native_export_arm64.go safe No malicious patterns detected; the file only contains variable assignments to internal function symbols for ARM64 SIMD routines, with no dynamic code execution, network activity, or filesystem manipulation.
internal/native/neon/parse_with_padding_arm64.go safe This file contains only a thin Go wrapper declaring an ARM64 assembly function using unsafe pointers and runtime escape marking; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or process spawning were identified.
internal/native/neon/parse_with_padding_subr_arm64.go safe No malicious patterns detected; the file is a generated assembly stub with only function pointer and stack size declarations.
internal/native/neon/quote_arm64.go safe No malicious patterns detected
internal/native/neon/quote_subr_arm64.go safe This is a generated assembly stub for a NEON quote function with no executable Go logic, network access, or suspicious behavior.
internal/native/neon/skip_array_arm64.go safe No malicious patterns detected
internal/native/neon/skip_array_subr_arm64.go safe No malicious patterns detected; this is a generated assembly bridge stub for a NEON SIMD JSON skip-array routine with no executable logic or external interaction.
internal/native/neon/skip_number_arm64.go safe No malicious patterns detected; the file is a generated, declarative Go binding to an assembly function for skipping numbers.
internal/native/neon/skip_number_subr_arm64.go safe No malicious patterns detected in this generated assembly stub file.
internal/native/neon/skip_object_arm64.go safe No malicious patterns detected; this is a standard generated Go assembly binding stub for a JSON object skipping function.
internal/native/neon/skip_object_subr_arm64.go safe No malicious patterns detected
internal/native/neon/skip_one_arm64.go safe No malicious patterns detected; the file is a benign Go assembly wrapper for a JSON skip function in the Sonic library.
internal/native/neon/skip_one_fast_arm64.go safe The file contains only a Go function declaration for an ARM64 assembly stub generated by scripts, with no malicious patterns detected.
internal/native/neon/skip_one_fast_subr_arm64.go safe Assembly-linked SIMD helper stub with no executable logic, network, filesystem, or import-time behavior; only build-tag gated symbol declarations.
internal/native/neon/skip_one_subr_arm64.go safe This is a generated Go assembly binding file with only function declarations and constants, containing no malicious patterns.
internal/native/neon/u64toa_arm64.go safe No malicious patterns detected
internal/native/neon/u64toa_subr_arm64.go safe This is a machine-generated assembly stub file for a Go NEON u64toa routine with no suspicious behavior, network calls, or dynamic execution.
internal/native/neon/unquote_arm64.go safe No malicious patterns detected
internal/native/neon/unquote_subr_arm64.go safe No malicious patterns detected; the file contains only an assembly trampoline declaration with no executable logic, network access, or file system interaction.
internal/native/neon/validate_one_arm64.go safe No malicious patterns detected; the file contains only a declaration and wrapper for an assembly-implemented validation function with no executable behavior at import time.
internal/native/neon/validate_one_subr_arm64.go safe No malicious patterns detected in the generated assembly binding stub; it contains only build tags, package declaration, function declaration, and variable/constant assignments with no external interactions or file system/network activity.
internal/native/neon/validate_utf8_arm64.go safe No malicious patterns detected; the file is a generated Go source with a standard ARM64 assembly declaration for UTF-8 validation.
internal/native/neon/validate_utf8_fast_arm64.go safe No malicious patterns detected; the file contains only a standard Go wrapper for an ARM64 NEON-optimized UTF-8 validation function generated by Sonic, with no network, file, process, or obfuscated behavior.
internal/native/neon/validate_utf8_fast_subr_arm64.go safe This is a generated assembly bridge file for UTF-8 validation with no executable logic, network, file system, or process manipulation, and no malicious patterns detected.
internal/native/neon/validate_utf8_subr_arm64.go safe No malicious patterns detected; the file contains only generated assembly entry-point declarations for a UTF-8 validation routine with no executable code, network access, file manipulation, or dynamic loading behaviors.
internal/native/neon/value_arm64.go safe No malicious patterns detected
internal/native/neon/value_subr_arm64.go safe No malicious patterns detected; the file is a minimal asm2asm-generated wrapper for the Go neon (Sonic) JSON library exposing a static subroutine entry point with no I/O, network, process, or dynamic execution behavior.
internal/native/neon/vnumber_arm64.go safe Cleared by Jev triage; no further analysis needed
internal/native/neon/vnumber_subr_arm64.go safe No malicious patterns detected
internal/native/neon/vsigned_arm64.go safe Cleared by Jev triage; no further analysis needed
internal/native/neon/vsigned_subr_arm64.go safe No malicious patterns detected
internal/native/neon/vstring_arm64.go safe Cleared by Jev triage; no further analysis needed
internal/native/neon/vstring_subr_arm64.go safe No malicious patterns detected; the file only declares a subroutine entry point and stack constants for generated assembly, with no network, filesystem, process, or dynamic execution activity.
internal/native/neon/vunsigned_arm64.go safe Cleared by Jev triage; no further analysis needed
internal/native/neon/vunsigned_subr_arm64.go safe This is a generated Go assembly stub for a NEON subroutine entry point with no malicious patterns, network activity, credential access, or dynamic execution.
internal/native/sse/f32toa.go safe No malicious patterns detected; the file is a generated Go assembly wrapper for float32-to-string conversion using unsafe pointers without any exfiltration, execution, or installation-time behavior.
internal/native/sse/f32toa_subr.go safe This file is auto-generated assembly metadata for a float-to-string conversion routine with no network, filesystem, process, or obfuscation activity; no malicious patterns detected.
internal/native/sse/f32toa_text_amd64.go safe This file contains generated x86-64 assembly byte slices and constant lookup tables for a floating-point-to-ASCII conversion routine; no malicious patterns, network access, process execution, or credential harvesting were detected.
internal/native/sse/f64toa_subr.go safe This is a generated Go assembly binding file for a floating-point to ASCII conversion routine from the sonic JSON library, containing only PC/stack metadata and function registration with no executable or network code.
internal/native/sse/get_by_path.go safe No malicious patterns detected in the generated SSE get_by_path wrapper; it only performs an unsafe-pointer FFI call to a native function without exfiltration, execution, network, or filesystem activity.
internal/native/sse/get_by_path_subr.go safe Generated assembly support file for the bytedance/sonic JSON library; contains only metadata tables and loader registrations, with no malicious patterns detected.
internal/native/sse/html_escape_subr.go safe No malicious patterns detected; this is a generated assembly metadata file for the bytedance/sonic JSON library defining stack/PC mapping for an HTML escape function.
internal/native/sse/html_escape_text_amd64.go safe No malicious patterns detected; the file contains only generated x86-64 assembly for HTML escaping with no network, filesystem, process, or dynamic code execution behavior.
internal/native/sse/i64toa_subr.go safe No malicious patterns detected; the file contains only generated metadata for assembly function registration in the sonic library.
internal/native/sse/i64toa_text_amd64.go safe This file contains only auto-generated assembly byte arrays and lookup tables for a 64-bit integer to ASCII conversion routine, with no malicious patterns detected.
internal/native/sse/lspace.go safe No malicious patterns detected; the file is a generated low-level SIMD/assembly bridging stub for bytedance/sonic with no network, credential, or dynamic execution behavior.
internal/native/sse/lspace_subr.go safe No malicious patterns detected; this is auto-generated assembly-bridge metadata for the sonic JSON library with no network, filesystem, process, or dynamic execution behavior.
internal/native/sse/lspace_text_amd64.go safe This is auto-generated x86-64 assembly for a whitespace-skipping routine in a JSON parsing library; no malicious patterns detected.
internal/native/sse/parse_with_padding_subr.go safe No malicious patterns detected; the file contains generated metadata for a native SSE parsing function from the sonic JSON library.
internal/native/sse/quote.go safe No malicious patterns detected
internal/native/sse/quote_subr.go safe This is generated assembly metadata for the sonic JSON library's SSE quote function, containing only stack frame and PCSP tables with no executable or suspicious logic.
internal/native/sse/skip_array.go safe No malicious patterns detected; the file contains legitimate SIMD/SSE parsing stub code from the sonic JSON library using unsafe pointers and a function variable bound to a native symbol.
internal/native/sse/skip_array_subr.go safe No malicious patterns detected
internal/native/sse/skip_number_subr.go safe No malicious patterns detected; the file contains only generated metadata for a Go assembly function in the sonic library.
internal/native/sse/skip_number_text_amd64.go safe No malicious patterns detected; the file contains generated x86-64 assembly data for a Go SSE number-skipping routine with no external I/O, network, process, or credential access.
internal/native/sse/skip_object.go safe No malicious patterns detected; the file is a generated Go wrapper for a native skip_object function using unsafe pointers without exfiltration, execution, or filesystem manipulation.
internal/native/sse/skip_object_subr.go safe No malicious patterns detected; the file is a generated assembly trampoline for the bytedance/sonic JSON library with no network, filesystem, process, or credential-access behavior.
internal/native/sse/skip_one.go safe No malicious patterns detected; the file is a generated low-level FFI binding for JSON parsing within the ByteDance sonic library.
internal/native/sse/skip_one_fast_subr.go safe No malicious patterns detected; the file only contains generated metadata for a platform-specific assembly routine in the bytedance/sonic library.
internal/native/sse/skip_one_fast_text_amd64.go safe This is a generated assembly byte array for a JSON SSE skip-scan routine; it contains no network, filesystem, process, or credential-access logic.
internal/native/sse/skip_one_subr.go safe No malicious patterns detected
internal/native/sse/u64toa.go safe No malicious patterns detected; the file is a generated Go wrapper for a native uint64-to-ASCII conversion routine using unsafe pointers but contains no exfiltration, credential harvesting, dynamic execution, or other red-flag behavior.
internal/native/sse/u64toa_subr.go safe Generated assembly metadata file contains only static function pointer tables and stack layout information for an integer-to-string conversion routine, with no executable code or malicious patterns.
internal/native/sse/u64toa_text_amd64.go safe This is a generated x86-64 assembly implementation of an unsigned 64-bit integer to ASCII conversion routine with only numeric lookup tables and no malicious behavior.
internal/native/sse/unquote.go safe No malicious patterns detected; the file contains a generated, low-level unquote wrapper using unsafe pointers from the ByteDance Sonic JSON library with no data exfiltration, credential harvesting, obfuscated execution, network access, or install-time behavior.
internal/native/sse/unquote_subr.go safe No malicious patterns detected; file is generated assembly metadata for a JSON unquote function with no executable, network, or credential-harvesting behavior.
internal/native/sse/unquote_text_amd64.go safe This file contains only precompiled amd64 assembly for a JSON string unquoting routine, with no network, filesystem, process, credential, or dynamic execution behavior.
internal/native/sse/validate_one.go safe The file is a generated Go wrapper for a native SSE validation function using unsafe pointers and cgo-style function pointers, with no malicious patterns detected.
internal/native/sse/validate_one_subr.go safe No malicious patterns detected; file contains only generated metadata for an assembly validation function with no network, filesystem, process, or dynamic execution activity.
internal/native/sse/validate_utf8.go safe No malicious patterns detected; the code is a generated internal wrapper for a UTF-8 validation function using unsafe pointers as expected for performance-critical native code.
internal/native/sse/validate_utf8_fast_subr.go safe No malicious patterns detected; the file contains only auto-generated metadata for an assembly-based UTF-8 validation function from the bytedance/sonic package.
internal/native/sse/validate_utf8_fast_text_amd64.go safe This is a generated AMD64 assembly implementation of a UTF-8 validation function with no malicious patterns, network calls, file access, or dynamic execution.
internal/native/sse/validate_utf8_subr.go safe This is an auto-generated Go assembly stub for UTF-8 validation in the bytedance/sonic library with no malicious patterns, network activity, credential access, or dynamic code execution.
internal/native/sse/validate_utf8_text_amd64.go safe This file contains only auto-generated x86-64 assembly bytecode implementing a UTF-8 validation routine for the Go runtime's internal SSE package, with no network, filesystem, process, or dynamic execution behavior.
internal/native/sse/value.go safe No malicious patterns detected; this is a legitimate JSON parser internal file using unsafe pointers for performance, typical of the ByteDance Sonic library.
internal/native/sse/value_subr.go safe No malicious patterns detected; the file contains only generated assembly metadata for a JSON parsing library with no network, filesystem, process, or dynamic code execution behavior.
internal/native/sse/vnumber_subr.go safe No malicious patterns detected; the file contains only generated assembly metadata and function registration for a JSON number parser, with no network, filesystem, process, or dynamic execution behavior.
internal/native/sse/vsigned.go safe No malicious patterns detected; the code only bridges Go to optimized assembly for JSON parsing, with no network, filesystem, exec, or credential access.
internal/native/sse/vsigned_subr.go safe No malicious patterns detected; the file contains generated assembly registration metadata for the Sonic JSON library's SSE implementation.
internal/native/sse/vsigned_text_amd64.go safe This file contains generated x86-64 assembly for a JSON number-parsing routine (vsigned), implementing standard integer parse logic with no network, filesystem, process, or credential access, and no malicious patterns.
internal/native/sse/vstring_subr.go safe No malicious patterns detected in this asm2asm-generated SSE vstring function registration file for the bytedance/sonic JSON library.
internal/native/sse/vstring_text_amd64.go safe This file contains only auto-generated AMD64 assembly (as byte arrays) for a SIMD-optimized JSON string validation routine from the sonic/amd64 SIMD library; no malicious patterns such as network calls, credential harvesting, code execution, or process spawning are present.
internal/native/sse/vunsigned.go safe No malicious patterns detected; the file only contains low-level native function bindings with unsafe pointers for JSON parsing, consistent with the ByteDance Sonic library.
internal/native/sse/vunsigned_subr.go safe Generated assembly metadata file with no executable code, network, filesystem, or dynamic execution patterns detected.
internal/native/sse/vunsigned_text_amd64.go safe This is a generated Go assembly file containing x86-64 machine code for an unsigned integer parsing routine, with no malicious patterns, network activity, file system access, or dynamic code execution.
internal/native/types/types.go safe No malicious patterns detected; this is legitimate JSON parser type definitions and pooling utilities from the Sonic library.
internal/optcaching/fcache.go safe Cleared by Jev triage; no further analysis needed
internal/resolver/fields.go safe Cleared by Jev triage; no further analysis needed
internal/resolver/resolver.go safe No malicious patterns detected; the code is a legitimate reflection-based struct field resolver from ByteDance's sonic JSON library.
internal/rt/assertI2I.go safe No malicious patterns detected; the file contains legitimate low-level Go runtime type assertion code using unsafe imports as part of ByteDance's sonic library, with no exfiltration, exec, network, or file system activity.
internal/rt/base64_compat.go safe Cleared by Jev triage; no further analysis needed
internal/rt/fastmem.go safe No malicious patterns detected; the code contains low-level unsafe memory manipulation utilities typical of high-performance parsers, with no data exfiltration, credential harvesting, obfuscation, or harmful behavior.
internal/rt/gotype_go126.go safe Cleared by Jev triage; no further analysis needed
internal/rt/gotype_legacy.go safe Cleared by Jev triage; no further analysis needed
internal/rt/int48.go safe Cleared by Jev triage; no further analysis needed
internal/rt/map.go safe The file defines a struct that mirrors Go runtime map iterator layout using unsafe.Pointer for compatibility with Go runtime internals, with no network, filesystem, process, installation, or obfuscated code patterns detected.
internal/rt/table.go safe Cleared by Jev triage; no further analysis needed
internal/rt/types.go safe No malicious patterns detected; the code only uses unsafe.Pointer for reflect type conversion and defines common Go type constants, with no network, filesystem, process, or dynamic execution activity.
internal/utils/skip.go safe The file contains only low-level string parsing utilities using unsafe pointer arithmetic for performance; no data exfiltration, credential harvesting, obfuscated payloads, network activity, process spawning, or other malicious patterns were found.
option/option.go safe Cleared by Jev triage; no further analysis needed
rawmessage.go safe Cleared by Jev triage; no further analysis needed
sonic.go safe Cleared by Jev triage; no further analysis needed
testdata/small.go safe Cleared by Jev triage; no further analysis needed
testdata/twitter.go safe Cleared by Jev triage; no further analysis needed
unquote/unquote_fallback.go safe Cleared by Jev triage; no further analysis needed
utf8/utf8.go safe No malicious patterns detected; the code is a UTF-8 validation and correction utility with no network, filesystem, process, or obfuscated behavior.
utf8/utf8_fallback.go safe Cleared by Jev triage; no further analysis needed

Scanned versions of github.com/bytedance/sonic

VersionVerdictFilesScanned
v1.15.4 Needs review 290 Oct 5, 2026

Frequently asked questions

Is github.com/bytedance/sonic safe to use?

No confirmed malware was found in github.com/bytedance/sonic@v1.15.4, but the review flagged 63 medium, 67 low severity findings for risky patterns worth checking before you rely on it.

Does github.com/bytedance/sonic contain malware?

No malware was identified in github.com/bytedance/sonic@v1.15.4 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was github.com/bytedance/sonic checked?

Togoder Security downloaded the published Go package and had an AI model read its 290 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan github.com/bytedance/sonic together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/bytedance/sonic@v1.15.4, cost nothing.

Related security reports