# github.com/grpc-ecosystem/go-grpc-middleware@v1.4.0 security report (Go)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-05T19:08:48.000Z
- Files reviewed: 70
- Findings: 5 medium, 7 low severity findings
- Report: https://security.togoder.click/go/github.com/grpc-ecosystem/go-grpc-middleware
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the Go package github.com/grpc-ecosystem/go-grpc-middleware@v1.4.0 on Oct 5, 2026. An AI review of 70 source files produced 5 medium, 7 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Sensitive data logging

Finding ID: `NPS-45331EA7534B`

File: `logging/kit/payload_interceptors.go:30`

The interceptors log full gRPC request and response payloads (including any credentials, tokens, PII, or secrets in protobuf messages) to the configured logger via logProtoMessageAsJson. This is a data-exposure risk if loggers are aggregated, shipped, or accessible to unauthorized parties. Mitigated somewhat by the decider callback, but logging full payloads by default is dangerous.

### [medium] Mutable Global Marshaller

Finding ID: `NPS-43C659957269`

File: `logging/logrus/payload_interceptors.go:16`

JsonPbMarshaller is an exported package-level variable that can be reassigned by any importing code. A malicious or compromised dependency could replace it with a custom marshaller that exfiltrates payload contents or performs side effects during marshaling.

### [medium] Sensitive Data Logging

Finding ID: `NPS-F1175FDA3164`

File: `logging/logrus/payload_interceptors.go:32`

The interceptors log full gRPC request and response payloads as JSON. Payloads can contain credentials, tokens, PII, or other secrets, and these are written to log destinations in cleartext. This is a design-level data exposure concern rather than malicious code.

### [medium] Unredacted Payload Capture

Finding ID: `NPS-247F086FC55C`

File: `logging/logrus/payload_interceptors.go:126`

logProtoMessageAsJson and the stream wrappers blindly serialize any proto.Message without field redaction or masking, ensuring all message content is logged regardless of sensitivity.

### [medium] Sensitive Data Logging

Finding ID: `NPS-2C94CB1D23A7`

File: `logging/zap/payload_interceptors.go:38`

The interceptors intentionally log full gRPC request and response payloads (including potentially sensitive data like credentials, tokens, PII) using JsonPbMarshaller. This could lead to sensitive information disclosure in log files if the decider is misconfigured or too permissive.

### [low] Potential secret leakage via dynamic marshaller

Finding ID: `NPS-909B849C095C`

File: `logging/kit/payload_interceptors.go:18`

JsonPbMarshaller is a mutable package-level variable that can be reassigned at runtime. If a malicious or compromised package reassigns it to an attacker-controlled marshaler, it could exfiltrate serialized payload data. Since this is set at the package level with no synchronization, any imported code can replace it.

### [low] Error content logged as request key

Finding ID: `NPS-949F75EF2FB2`

File: `logging/kit/payload_interceptors.go:114`

In logProtoMessageAsJson, when JSON marshaling fails, the error object is logged under the same key intended for the payload. Depending on the error, this could inadvertently leak internal details, though this is minor.

### [low] Global Mutable State

Finding ID: `NPS-1C5E5190399C`

File: `logging/zap/payload_interceptors.go:18`

JsonPbMarshaller is an exported package-level variable that can be reassigned at runtime by any code importing this package. An attacker with code execution could replace it with a malicious marshaler to exfiltrate protobuf contents or inject data into logs, though this is not malicious on its own.

### [low] Reflection-Based Serialization

Finding ID: `NPS-71CE5515BDBC`

File: `logging/zap/payload_interceptors.go:137`

Use of AddReflected and custom MarshalJSON alongside proto.Message type assertion means arbitrary protobuf message contents are serialized into logs. Combined with a permissive decider, this amplifies the sensitive-data-logging risk.

### [low] Local network listener for tests

Finding ID: `NPS-58BC70791E72`

File: `testing/interceptor_suite.go:57`

The suite binds to 127.0.0.1:0 and serves gRPC for test purposes only. No external network communication or data exfiltration is present.

### [low] Insecure gRPC client option behind test flag

Finding ID: `NPS-148868CAF7B7`

File: `testing/interceptor_suite.go:128`

When the -use_tls flag is false, the client uses grpc.WithInsecure(). This is a test-only convenience flag and does not represent malicious behavior, though it disables transport security in test environments.

### [low] Test-only self-signed certificate generation

Finding ID: `NPS-EF9F5A8FD1CD`

File: `testing/interceptor_suite.go:171`

generateCertAndKey generates a self-signed RSA certificate/key pair for TLS testing. It is used only within the test suite to create in-memory TLS credentials for a localhost gRPC server and client. No private key is exfiltrated or persisted to disk.

## Files reviewed

- `logging/kit/payload_interceptors.go` (medium): The code is a legitimate gRPC logging interceptor but logs full request/response payloads, which can expose sensitive data if not carefully gated by the decider; no outright malicious patterns (exfiltration, backdoors, exec, credential harvesting) are present.
- `logging/logrus/payload_interceptors.go` (medium): No overt malicious patterns (exfiltration, exec, credential harvesting, backdoors) were found, but the library deliberately logs full gRPC payloads in JSON form and exposes a mutable global marshaller, creating significant sensitive-data-exposure risk in production deployments.
- `logging/zap/payload_interceptors.go` (medium): Legitimate gRPC logging middleware with no malicious code, but it intentionally logs full request/response payloads which can leak sensitive data if not carefully gated by the decider.
- `auth/auth.go` (safe): Cleared by Jev triage; no further analysis needed
- `auth/doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `auth/metadata.go` (safe): No malicious patterns detected
- `chain.go` (safe): Cleared by Jev triage; no further analysis needed
- `doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `logging/common.go` (safe): Cleared by Jev triage; no further analysis needed
- `logging/doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `logging/kit/client_interceptors.go` (safe): No malicious patterns detected; the code is a standard gRPC logging interceptor that only logs call metadata and does not perform any suspicious operations.
- `logging/kit/ctxkit/context.go` (safe): Cleared by Jev triage; no further analysis needed
- `logging/kit/ctxkit/doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `logging/kit/doc.go` (safe): No malicious patterns detected; the file contains only package documentation comments and a package declaration.
- `logging/kit/options.go` (safe): Cleared by Jev triage; no further analysis needed
- `logging/kit/server_interceptors.go` (safe): Cleared by Jev triage; no further analysis needed
- `logging/logrus/client_interceptors.go` (safe): No malicious patterns detected
- `logging/logrus/context.go` (safe): Cleared by Jev triage; no further analysis needed
- `logging/logrus/ctxlogrus/context.go` (safe): Cleared by Jev triage; no further analysis needed
- `logging/logrus/ctxlogrus/doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `logging/logrus/ctxlogrus/noop.go` (safe): Cleared by Jev triage; no further analysis needed
- `logging/logrus/doc.go` (safe): No malicious patterns detected in the provided Go documentation file.
- `logging/logrus/grpclogger.go` (safe): No malicious patterns detected
- `logging/logrus/options.go` (safe): Cleared by Jev triage; no further analysis needed
- `logging/logrus/server_interceptors.go` (safe): Cleared by Jev triage; no further analysis needed
- `logging/settable/doc.go` (safe): No malicious patterns detected
- `logging/settable/logsettable.go` (safe): No malicious patterns detected; the code is a benign thread-safe gRPC logger wrapper.
- `logging/zap/client_interceptors.go` (safe): No malicious patterns detected; the code is a standard gRPC logging interceptor with no data exfiltration, credential harvesting, or dynamic code execution.
- `logging/zap/context.go` (safe): Cleared by Jev triage; no further analysis needed
- `logging/zap/ctxzap/context.go` (safe): Cleared by Jev triage; no further analysis needed
- `logging/zap/ctxzap/doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `logging/zap/doc.go` (safe): No malicious patterns detected
- `logging/zap/grpclogger.go` (safe): No malicious patterns detected; the code is a benign gRPC logging adapter for zap with no data exfiltration, credential harvesting, or dynamic code execution.
- `logging/zap/options.go` (safe): Cleared by Jev triage; no further analysis needed
- `logging/zap/server_interceptors.go` (safe): Cleared by Jev triage; no further analysis needed
- `ratelimit/doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `ratelimit/ratelimit.go` (safe): Cleared by Jev triage; no further analysis needed
- `recovery/doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `recovery/interceptors.go` (safe): No malicious patterns detected
- `recovery/options.go` (safe): Cleared by Jev triage; no further analysis needed
- `retry/backoff.go` (safe): Cleared by Jev triage; no further analysis needed
- `retry/doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `retry/options.go` (safe): Cleared by Jev triage; no further analysis needed
- `retry/retry.go` (safe): No malicious patterns detected; this is a legitimate gRPC retry middleware library with standard client interceptor logic.
- `tags/context.go` (safe): Cleared by Jev triage; no further analysis needed
- `tags/doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `tags/fieldextractor.go` (safe): The code is a benign gRPC context tags field extractor using reflection; no malicious patterns such as data exfiltration, command execution, or obfuscation were found.
- `tags/interceptors.go` (safe): No malicious patterns detected
- `tags/logrus/context.go` (safe): Cleared by Jev triage; no further analysis needed
- `tags/options.go` (safe): Cleared by Jev triage; no further analysis needed
- `tags/zap/context.go` (safe): Cleared by Jev triage; no further analysis needed
- `testing/gogotestproto/fields.pb.go` (safe): Generated Go protobuf code with no malicious patterns, network calls, or install-time side effects
- `testing/interceptor_suite.go` (safe): The file is a standard gRPC interceptor test suite that generates an in-memory self-signed certificate for local TLS testing and contains no malicious patterns.
- `testing/mutex_readerwriter.go` (safe): Cleared by Jev triage; no further analysis needed
- `testing/pingservice.go` (safe): Cleared by Jev triage; no further analysis needed
- `testing/testproto/test.manual_extractfields.pb.go` (safe): Cleared by Jev triage; no further analysis needed
- `testing/testproto/test.manual_validator.pb.go` (safe): Cleared by Jev triage; no further analysis needed
- `testing/testproto/test.pb.go` (safe): Standard protoc-gen-go generated gRPC service definitions and message types with no malicious patterns, obfuscated code, network calls, file access, or command execution.
- `tracing/opentracing/client_interceptors.go` (safe): No malicious patterns detected
- `tracing/opentracing/doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `tracing/opentracing/id_extract.go` (safe): No malicious patterns detected; the code is a benign gRPC OpenTracing middleware utility that extracts trace IDs into context tags without any exfiltration, execution, or credential-harvesting behavior.
- `tracing/opentracing/metadata.go` (safe): Cleared by Jev triage; no further analysis needed
- `tracing/opentracing/options.go` (safe): Cleared by Jev triage; no further analysis needed
- `tracing/opentracing/server_interceptors.go` (safe): This is a legitimate OpenTracing gRPC middleware interceptor with no malicious patterns, no data exfiltration, no credential harvesting, and no dynamic code execution.
- `util/backoffutils/backoff.go` (safe): Cleared by Jev triage; no further analysis needed
- `util/metautils/doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `util/metautils/nicemd.go` (safe): Cleared by Jev triage; no further analysis needed
- `validator/doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `validator/validator.go` (safe): Cleared by Jev triage; no further analysis needed
- `wrappers.go` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
