Togoder security

Go package security report

github.com/grpc-ecosystem/go-grpc-middleware@v1.4.0 security report

Risky patterns found that deserve a look.

Needs review Version v1.4.0 Files reviewed 70 Size 195.0 KB Scanned

Summary

Togoder Security scanned the Go package github.com/grpc-ecosystem/go-grpc-middleware@v1.4.0 on Oct 5, 2026. An AI review of 70 source files produced 5 medium, 7 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

0
critical
0
high
5
medium
7
low

Findings 12

medium

Sensitive data logging

NPS-45331EA7534B

The interceptors log full gRPC request and response payloads (including any credentials, tokens, PII, or secrets in protobuf messages) to the configured logger via logProtoMessageAsJson. This is a data-exposure risk if loggers are aggregated, shipped, or accessible to unauthorized parties. Mitigated somewhat by the decider callback, but logging full payloads by default is dangerous.

logging/kit/payload_interceptors.go:30
medium

Mutable Global Marshaller

NPS-43C659957269

JsonPbMarshaller is an exported package-level variable that can be reassigned by any importing code. A malicious or compromised dependency could replace it with a custom marshaller that exfiltrates payload contents or performs side effects during marshaling.

logging/logrus/payload_interceptors.go:16
medium

Sensitive Data Logging

NPS-F1175FDA3164

The interceptors log full gRPC request and response payloads as JSON. Payloads can contain credentials, tokens, PII, or other secrets, and these are written to log destinations in cleartext. This is a design-level data exposure concern rather than malicious code.

logging/logrus/payload_interceptors.go:32
medium

Unredacted Payload Capture

NPS-247F086FC55C

logProtoMessageAsJson and the stream wrappers blindly serialize any proto.Message without field redaction or masking, ensuring all message content is logged regardless of sensitivity.

logging/logrus/payload_interceptors.go:126
medium

Sensitive Data Logging

NPS-2C94CB1D23A7

The interceptors intentionally log full gRPC request and response payloads (including potentially sensitive data like credentials, tokens, PII) using JsonPbMarshaller. This could lead to sensitive information disclosure in log files if the decider is misconfigured or too permissive.

logging/zap/payload_interceptors.go:38
low

Potential secret leakage via dynamic marshaller

NPS-909B849C095C

JsonPbMarshaller is a mutable package-level variable that can be reassigned at runtime. If a malicious or compromised package reassigns it to an attacker-controlled marshaler, it could exfiltrate serialized payload data. Since this is set at the package level with no synchronization, any imported code can replace it.

logging/kit/payload_interceptors.go:18
low

Error content logged as request key

NPS-949F75EF2FB2

In logProtoMessageAsJson, when JSON marshaling fails, the error object is logged under the same key intended for the payload. Depending on the error, this could inadvertently leak internal details, though this is minor.

logging/kit/payload_interceptors.go:114
low

Global Mutable State

NPS-1C5E5190399C

JsonPbMarshaller is an exported package-level variable that can be reassigned at runtime by any code importing this package. An attacker with code execution could replace it with a malicious marshaler to exfiltrate protobuf contents or inject data into logs, though this is not malicious on its own.

logging/zap/payload_interceptors.go:18
low

Reflection-Based Serialization

NPS-71CE5515BDBC

Use of AddReflected and custom MarshalJSON alongside proto.Message type assertion means arbitrary protobuf message contents are serialized into logs. Combined with a permissive decider, this amplifies the sensitive-data-logging risk.

logging/zap/payload_interceptors.go:137
low

Local network listener for tests

NPS-58BC70791E72

The suite binds to 127.0.0.1:0 and serves gRPC for test purposes only. No external network communication or data exfiltration is present.

testing/interceptor_suite.go:57
low

Insecure gRPC client option behind test flag

NPS-148868CAF7B7

When the -use_tls flag is false, the client uses grpc.WithInsecure(). This is a test-only convenience flag and does not represent malicious behavior, though it disables transport security in test environments.

testing/interceptor_suite.go:128
low

Test-only self-signed certificate generation

NPS-EF9F5A8FD1CD

generateCertAndKey generates a self-signed RSA certificate/key pair for TLS testing. It is used only within the test suite to create in-memory TLS credentials for a localhost gRPC server and client. No private key is exfiltrated or persisted to disk.

testing/interceptor_suite.go:171

Files reviewed

FileVerdictWhat the reviewer saw
logging/kit/payload_interceptors.go medium The code is a legitimate gRPC logging interceptor but logs full request/response payloads, which can expose sensitive data if not carefully gated by the decider; no outright malicious patterns (exfiltration, backdoors, exec, credential harvesting) are present.
logging/logrus/payload_interceptors.go medium No overt malicious patterns (exfiltration, exec, credential harvesting, backdoors) were found, but the library deliberately logs full gRPC payloads in JSON form and exposes a mutable global marshaller, creating significant sensitive-data-exposure risk in production deployments.
logging/zap/payload_interceptors.go medium Legitimate gRPC logging middleware with no malicious code, but it intentionally logs full request/response payloads which can leak sensitive data if not carefully gated by the decider.
auth/auth.go safe Cleared by Jev triage; no further analysis needed
auth/doc.go safe Cleared by Jev triage; no further analysis needed
auth/metadata.go safe No malicious patterns detected
chain.go safe Cleared by Jev triage; no further analysis needed
doc.go safe Cleared by Jev triage; no further analysis needed
logging/common.go safe Cleared by Jev triage; no further analysis needed
logging/doc.go safe Cleared by Jev triage; no further analysis needed
logging/kit/client_interceptors.go safe No malicious patterns detected; the code is a standard gRPC logging interceptor that only logs call metadata and does not perform any suspicious operations.
logging/kit/ctxkit/context.go safe Cleared by Jev triage; no further analysis needed
logging/kit/ctxkit/doc.go safe Cleared by Jev triage; no further analysis needed
logging/kit/doc.go safe No malicious patterns detected; the file contains only package documentation comments and a package declaration.
logging/kit/options.go safe Cleared by Jev triage; no further analysis needed
logging/kit/server_interceptors.go safe Cleared by Jev triage; no further analysis needed
logging/logrus/client_interceptors.go safe No malicious patterns detected
logging/logrus/context.go safe Cleared by Jev triage; no further analysis needed
logging/logrus/ctxlogrus/context.go safe Cleared by Jev triage; no further analysis needed
logging/logrus/ctxlogrus/doc.go safe Cleared by Jev triage; no further analysis needed
logging/logrus/ctxlogrus/noop.go safe Cleared by Jev triage; no further analysis needed
logging/logrus/doc.go safe No malicious patterns detected in the provided Go documentation file.
logging/logrus/grpclogger.go safe No malicious patterns detected
logging/logrus/options.go safe Cleared by Jev triage; no further analysis needed
logging/logrus/server_interceptors.go safe Cleared by Jev triage; no further analysis needed
Show 45 more files
FileVerdictWhat the reviewer saw
logging/settable/doc.go safe No malicious patterns detected
logging/settable/logsettable.go safe No malicious patterns detected; the code is a benign thread-safe gRPC logger wrapper.
logging/zap/client_interceptors.go safe No malicious patterns detected; the code is a standard gRPC logging interceptor with no data exfiltration, credential harvesting, or dynamic code execution.
logging/zap/context.go safe Cleared by Jev triage; no further analysis needed
logging/zap/ctxzap/context.go safe Cleared by Jev triage; no further analysis needed
logging/zap/ctxzap/doc.go safe Cleared by Jev triage; no further analysis needed
logging/zap/doc.go safe No malicious patterns detected
logging/zap/grpclogger.go safe No malicious patterns detected; the code is a benign gRPC logging adapter for zap with no data exfiltration, credential harvesting, or dynamic code execution.
logging/zap/options.go safe Cleared by Jev triage; no further analysis needed
logging/zap/server_interceptors.go safe Cleared by Jev triage; no further analysis needed
ratelimit/doc.go safe Cleared by Jev triage; no further analysis needed
ratelimit/ratelimit.go safe Cleared by Jev triage; no further analysis needed
recovery/doc.go safe Cleared by Jev triage; no further analysis needed
recovery/interceptors.go safe No malicious patterns detected
recovery/options.go safe Cleared by Jev triage; no further analysis needed
retry/backoff.go safe Cleared by Jev triage; no further analysis needed
retry/doc.go safe Cleared by Jev triage; no further analysis needed
retry/options.go safe Cleared by Jev triage; no further analysis needed
retry/retry.go safe No malicious patterns detected; this is a legitimate gRPC retry middleware library with standard client interceptor logic.
tags/context.go safe Cleared by Jev triage; no further analysis needed
tags/doc.go safe Cleared by Jev triage; no further analysis needed
tags/fieldextractor.go safe The code is a benign gRPC context tags field extractor using reflection; no malicious patterns such as data exfiltration, command execution, or obfuscation were found.
tags/interceptors.go safe No malicious patterns detected
tags/logrus/context.go safe Cleared by Jev triage; no further analysis needed
tags/options.go safe Cleared by Jev triage; no further analysis needed
tags/zap/context.go safe Cleared by Jev triage; no further analysis needed
testing/gogotestproto/fields.pb.go safe Generated Go protobuf code with no malicious patterns, network calls, or install-time side effects
testing/interceptor_suite.go safe The file is a standard gRPC interceptor test suite that generates an in-memory self-signed certificate for local TLS testing and contains no malicious patterns.
testing/mutex_readerwriter.go safe Cleared by Jev triage; no further analysis needed
testing/pingservice.go safe Cleared by Jev triage; no further analysis needed
testing/testproto/test.manual_extractfields.pb.go safe Cleared by Jev triage; no further analysis needed
testing/testproto/test.manual_validator.pb.go safe Cleared by Jev triage; no further analysis needed
testing/testproto/test.pb.go safe Standard protoc-gen-go generated gRPC service definitions and message types with no malicious patterns, obfuscated code, network calls, file access, or command execution.
tracing/opentracing/client_interceptors.go safe No malicious patterns detected
tracing/opentracing/doc.go safe Cleared by Jev triage; no further analysis needed
tracing/opentracing/id_extract.go safe No malicious patterns detected; the code is a benign gRPC OpenTracing middleware utility that extracts trace IDs into context tags without any exfiltration, execution, or credential-harvesting behavior.
tracing/opentracing/metadata.go safe Cleared by Jev triage; no further analysis needed
tracing/opentracing/options.go safe Cleared by Jev triage; no further analysis needed
tracing/opentracing/server_interceptors.go safe This is a legitimate OpenTracing gRPC middleware interceptor with no malicious patterns, no data exfiltration, no credential harvesting, and no dynamic code execution.
util/backoffutils/backoff.go safe Cleared by Jev triage; no further analysis needed
util/metautils/doc.go safe Cleared by Jev triage; no further analysis needed
util/metautils/nicemd.go safe Cleared by Jev triage; no further analysis needed
validator/doc.go safe Cleared by Jev triage; no further analysis needed
validator/validator.go safe Cleared by Jev triage; no further analysis needed
wrappers.go safe Cleared by Jev triage; no further analysis needed

Frequently asked questions

Is github.com/grpc-ecosystem/go-grpc-middleware safe to use?

No confirmed malware was found in github.com/grpc-ecosystem/go-grpc-middleware@v1.4.0, but the review flagged 5 medium, 7 low severity findings for risky patterns worth checking before you rely on it.

Does github.com/grpc-ecosystem/go-grpc-middleware contain malware?

No malware was identified in github.com/grpc-ecosystem/go-grpc-middleware@v1.4.0 when Togoder Security scanned it on Oct 5, 2026. A new version can still introduce malicious code, so scan the exact versions in your lockfile.

How was github.com/grpc-ecosystem/go-grpc-middleware checked?

Togoder Security downloaded the published Go package and had an AI model read its 70 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan github.com/grpc-ecosystem/go-grpc-middleware together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in github.com/grpc-ecosystem/go-grpc-middleware@v1.4.0, cost nothing.

Related security reports