# github.com/quagmt/udecimal@v1.10.1 security report (Go)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-05T19:09:06.000Z
- Files reviewed: 6
- Findings: 2 medium severity findings
- Report: https://security.togoder.click/go/github.com/quagmt/udecimal
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the Go package github.com/quagmt/udecimal@v1.10.1 on Oct 5, 2026. An AI review of 6 source files produced 2 medium severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Unsafe memory manipulation

Finding ID: `NPS-D3101D0F8BDE`

File: `codec.go:287`

The function unsafeStringToBytes uses unsafe.Slice and unsafe.StringData to reinterpret a string's underlying bytes as a mutable []byte without copying. This violates Go's string immutability and could lead to memory corruption if the returned slice is modified. It is used in MarshalJSON to return a byte slice backed by a string, which is then returned to the caller. While not overtly malicious, this is a dangerous pattern that can cause undefined behavior and is generally considered a security risk.

### [medium] Potential JSON output corruption

Finding ID: `NPS-CA163AFFDDB9`

File: `codec.go:295`

In MarshalJSON, the result of d.stringU128(true, true) is converted to a []byte via unsafeStringToBytes. The string is built in appendBuffer with a fixed-size local buffer and then copied into a new slice. However, using unsafe to convert the string back to a byte slice means the returned byte slice shares memory with the string. If the caller modifies the byte slice, it would corrupt the string, though in practice the caller (json.Marshal) typically does not. Still, it is a fragile and risky pattern.

## Files reviewed

- `codec.go` (medium): The code contains unsafe memory manipulation via unsafe.Slice/unsafe.StringData, which is a risky but potentially performance-motivated pattern; no overt malicious behavior detected.
- `bint.go` (safe): Cleared by Jev triage; no further analysis needed
- `decimal.go` (safe): Cleared by Jev triage; no further analysis needed
- `doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `u128.go` (safe): Cleared by Jev triage; no further analysis needed
- `u256.go` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
