# golang.org/x/crypto@v0.57.0 security report (Go)

- Verdict: **Critical risk** (risk level: critical)
- Scanned: 2026-10-05T19:09:28.000Z
- Files reviewed: 171
- Findings: 1 critical, 3 high, 18 medium, 28 low severity findings
- Report: https://security.togoder.click/go/golang.org/x/crypto
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the Go package golang.org/x/crypto@v0.57.0 on Oct 5, 2026. An AI review of 171 source files produced 1 critical, 3 high, 18 medium, 28 low severity findings. At least one finding describes dangerous behavior such as code that runs at install time, credential access or data exfiltration. Do not install this version until you have reviewed the findings below.

## Findings

### [critical] dangerous_default_deprecation

Finding ID: `NPS-C137C547738E`

File: `openpgp/read.go:8`

The package documentation explicitly states the package is 'unsafe by design' and has 'numerous known security issues' and 'should not be used'. This is a critical security concern for any application relying on it, as it may contain unpatched vulnerabilities leading to message forgery, decryption failures, or other cryptographic weaknesses.

### [high] insufficient_signature_verification

Finding ID: `NPS-5A5ECBAB5556`

File: `openpgp/read.go:222`

The ReadMessage function only sets up signature verification if the signer key is present in the keyring (md.SignedBy != nil). If the signer's key is not found, the signature is never checked, and the data is treated as unsigned. This can allow forged messages or tampering, as attackers could omit the signature or use a key not in the keyring.

### [high] mdc_check_timing

Finding ID: `NPS-94D3D7DBD1BF`

File: `openpgp/read.go:316`

The integrity check (MDC) is only performed when the UnverifiedBody is read to EOF. If the caller does not fully consume the body, the check is skipped. This can lead to acceptance of tampered messages if the application does not adhere to the documented requirement to read until EOF. Applications may mistakenly trust unverified data.

### [high] Deprecated and unmaintained cryptography

Finding ID: `NPS-A03368E29BB0`

File: `openpgp/s2k/s2k.go:9`

The package is explicitly documented as unsafe by design, has known security issues, and is not maintained, meaning vulnerabilities will not be patched.

### [medium] Command execution with user-controlled script

Finding ID: `NPS-A64203707463`

File: `acme/internal/acmeprobe/prober.go:320`

The runDNS01 function executes an arbitrary script specified via the -s command-line flag using exec.CommandContext. The script is invoked with the challenge name and token as arguments. While this is intentional for the ACME prober's DNS-01 challenge provisioning, it represents a process-spawning capability driven by external input. If an attacker can control the -s flag or influence its value (e.g., via a wrapper or CI harness), arbitrary commands could be executed with the privileges of the prober.

### [medium] Insecure cryptographic implementation

Finding ID: `NPS-BB0E27FFBB9C`

File: `openpgp/elgamal/elgamal.go`

The package's own documentation explicitly states: 'this package doesn't protect against side-channel attacks' and it embeds PKCS#1 v1.5 padding which the code itself acknowledges creates a padding oracle vulnerable to Bleichenbacher-style adaptive chosen ciphertext attacks. While not overtly malicious, shipping a known-insecure crypto primitive that may be silently used by downstream consumers poses a real security risk to applications relying on it.

### [medium] Deprecated and Unsafe Cryptography

Finding ID: `NPS-6452FBEC3A89`

File: `openpgp/packet/packet.go:6`

The package itself is marked as Deprecated and states it 'is unsafe by design, and has numerous known security issues. It is not maintained, and should not be used.' This is a significant security concern as it may contain known vulnerabilities (e.g., CVE-2023-... for Go OpenPGP) and lacks security updates.

### [medium] Insecure Use of crypto/des

Finding ID: `NPS-87B888E46E5B`

File: `openpgp/packet/packet.go:26`

The package imports crypto/des which is considered insecure for modern use, as DES and 3DES are deprecated. This aligns with the package's deprecated status and known issues.

### [medium] Weak Cryptography Algorithms

Finding ID: `NPS-8776DA6C7EB0`

File: `openpgp/packet/packet.go:351`

The code supports weak ciphers such as Cipher3DES and CipherCAST5, and deprecated public key algorithms like PubKeyAlgoRSAEncryptOnly and PubKeyAlgoRSASignOnly. Use of these algorithms is discouraged as they may be vulnerable to attacks.

### [medium] Lack of Error Handling in Cipher Initialization

Finding ID: `NPS-E43F34652C92`

File: `openpgp/packet/packet.go:430`

The new method for CipherFunction ignores errors from des.NewTripleDESCipher, cast5.NewCipher, and aes.NewCipher. If an invalid key length is provided (e.g., due to a malformed packet), the returned block cipher may be nil or incomplete, which could lead to a panic or unpredictable behavior when used later.

### [medium] Deprecated/insecure key version support

Finding ID: `NPS-F5D655B7935D`

File: `openpgp/packet/public_key_v3.go:24`

Implements support for V3 OpenPGP public keys, which are explicitly documented as less secure and should not be used for signing or encrypting. The code allows parsing and signature verification of deprecated V3 keys, which could enable downgrade attacks if callers don't enforce version restrictions.

### [medium] Weak cryptographic algorithm

Finding ID: `NPS-0FD5AAFE1720`

File: `openpgp/packet/public_key_v3.go:82`

Uses MD5 for fingerprint computation in setFingerPrintAndKeyId. MD5 is cryptographically broken and unsuitable for security-sensitive operations, though this is mandated by RFC 4880 for v3 key fingerprints. This is a legacy compatibility requirement, not malicious, but represents a security weakness.

### [medium] Unvalidated RSA key parameters

Finding ID: `NPS-7DBA4348AF51`

File: `openpgp/packet/public_key_v3.go:95`

In parseRSA, the RSA modulus and exponent are parsed from network input with minimal validation. While there is a check that the modulus is at least 8 bytes and the exponent is at most 3 bytes, there is no check on minimum RSA modulus size (bit length), allowing potentially very weak RSA keys (e.g., tiny moduli) to be accepted.

### [medium] Unbounded memory allocation

Finding ID: `NPS-BBD2F866F2A2`

File: `openpgp/packet/signature.go:97`

The parse function reads a 2-byte length for hashed subpackets (`hashedSubpacketsLength`) and allocates a buffer `sig.HashSuffix` of size `l+6` where `l = 6 + hashedSubpacketsLength`. An attacker can specify a large length (up to 65535) causing a relatively large allocation. More critically, later it reads a 2-byte length for unhashed subpackets and allocates `make([]byte, unhashedSubpacketsLength)` without any upper bound check. This can lead to excessive memory allocation (up to 64KB per signature packet), which could be exploited for memory exhaustion in a denial-of-service attack.

### [medium] Potential panic on untrusted input

Finding ID: `NPS-AB6301D7DFB7`

File: `openpgp/packet/signature.go:134`

The parse function contains a `panic("unreachable")` in the default case of the public key algorithm switch. Although the algorithm is validated earlier, if an attacker can control the input in a way that bypasses the earlier validation (e.g., via a crafted packet that causes the switch cases to mismatch), it could lead to a denial-of-service (panic). This is a robustness issue in a security-critical parser.

### [medium] Error handling inconsistency

Finding ID: `NPS-3F0A6068859B`

File: `openpgp/packet/signature.go:202`

In `parseSignatureSubpacket`, for certain subpacket types (e.g., signatureExpirationSubpacket, keyExpirationSubpacket, prefSymmetricAlgosSubpacket, etc.), if `!isHashed`, the function returns early with `return` (nil error, nil rest). This effectively skips parsing the subpacket and returns `rest` as nil. This could cause the caller to stop processing the remaining subpackets prematurely, potentially leading to incorrect parsing or bypassing of subsequent subpackets. An attacker could craft a packet to exploit this to hide malicious data or cause misinterpretation.

### [medium] Use of unsafe type assertions

Finding ID: `NPS-58A6E245AB5D`

File: `openpgp/packet/signature.go:374`

In the Sign function, there are type assertions like `priv.PrivateKey.(crypto.Signer)` without checking the `ok` boolean. If the private key is not of the expected type, this will panic. While the caller might ensure the correct type, this is a robustness issue that could lead to a crash if the API is misused. In a security context, unexpected panics can be exploited for denial-of-service.

### [medium] infinite_prompt_loop

Finding ID: `NPS-F7D5FE2BC409`

File: `openpgp/read.go:165`

The PromptFunction is called in a loop that continues forever if the prompt returns a passphrase or key that is incorrect. This could lead to a denial-of-service or user frustration, as there is no limit on retries. In automated systems, this could hang indefinitely, potentially causing resource exhaustion.

### [medium] panic_unreachable

Finding ID: `NPS-3EF5239912F1`

File: `openpgp/read.go:477`

Several places contain panic statements that are supposedly unreachable but could be triggered by malicious input causing unexpected code paths. For example, in CheckDetachedSignature, a panic can occur if the loop exits without finding keys, but the condition is checked before the loop; however, if the keyring's KeysByIdUsage returns an empty slice, the subsequent code may panic. This could be exploited for denial-of-service.

### [medium] Weak default cryptographic parameters

Finding ID: `NPS-5E84C491C0D8`

File: `openpgp/s2k/s2k.go:44`

The package defaults to SHA1 and a low iteration count (65536) for key derivation when Config is nil, which is weak by modern standards and could enable brute-force attacks on derived keys.

### [medium] Insecure cryptography (DSA 1024/160, SHA-1, deprecated protocol)

Finding ID: `NPS-AB69D2306FCD`

File: `otr/otr.go`

The package uses DSA with 1024-bit parameters (L1024N160) and SHA-1 for MACs, which are weak/deprecated. This is inherent to the OTRv2 protocol design and is documented as deprecated, but it constitutes a cryptographic weakness rather than a malicious pattern.

### [medium] Agent forwarding

Finding ID: `NPS-FEA1F45359DE`

File: `ssh/agent/forward.go`

The code implements SSH agent forwarding, which if misused can allow an attacker with access to the remote host to use the local SSH agent to authenticate to other systems. This is a legitimate feature but carries inherent security risks if not properly controlled.

### [low] Credential/account material generation and handling

Finding ID: `NPS-E8F9EFD44DBE`

File: `acme/internal/acmeprobe/prober.go:130`

The tool generates an ECDSA account key and CSR key, registers an ACME account, and then deactivates it. No exfiltration of credentials to third parties is present. However, the process handles private keys in memory and prints certificate details (serial, subject, leaf PEM) to logs, which could leak sensitive certificate metadata if logs are accessible.

### [low] Network server binding to user-specified address

Finding ID: `NPS-FF9E50FFE801`

File: `acme/internal/acmeprobe/prober.go:250`

The prober spins up HTTP/TLS servers on an address taken directly from the -a command-line flag (p.localAddr). Binding to user-controlled addresses (including potentially 0.0.0.0 or public interfaces) without validation could expose the challenge server beyond intended scopes. In the context of this tool, the user is expected to set this deliberately, but it is a potential misconfiguration risk.

### [low] Environment variable read

Finding ID: `NPS-61B63EAE447E`

File: `internal/testenv/exec.go:37`

Reads GO_TEST_TIMEOUT_SCALE environment variable to adjust timeout scaling. This is a benign test configuration variable, not credential or sensitive data harvesting.

### [low] Process spawning (os/exec)

Finding ID: `NPS-1A5F603D77CE`

File: `internal/testenv/exec.go:68`

The code uses os/exec to spawn subprocesses based on user-provided command and arguments. This is expected for a test helper library and is not malicious. The commands are explicitly provided by the caller (test code).

### [low] Reflection for compatibility

Finding ID: `NPS-49AC3DAB1EEC`

File: `internal/testenv/exec.go:82`

Uses reflection to conditionally set Cancel and WaitDelay fields on exec.Cmd for Go version compatibility. The reflected field names are hardcoded and legitimate (they are part of exec.Cmd).

### [low] Deprecated Cryptographic Algorithm

Finding ID: `NPS-93A178B6A95E`

File: `md4/md4.go:7`

MD4 is cryptographically broken and unsuitable for security purposes. The package itself documents this deprecation. This is a known weakness but not a malicious pattern.

### [low] Deprecated / abandoned dependency

Finding ID: `NPS-B0B99EA7C7FF`

File: `openpgp/elgamal/elgamal.go`

The package and the parent golang.org/x/crypto/openpgp are explicitly deprecated, with known compatibility and security issues referenced (eprint.iacr.org/2021/923). Continued use introduces a supply-chain risk of relying on unmaintained security-critical code.

### [low] Constant-time best effort weaknesses

Finding ID: `NPS-A5C1E45F5D7B`

File: `openpgp/elgamal/elgamal.go`

Decrypt attempts constant-time comparison with subtle.ConstantTimeSelect/ByteEq, but iterating over variable-length big.Int.Bytes() output and slicing em[index+1:] leaks length information and does not fully defend the padding check, consistent with the package's own warning about side channels.

### [low] Potential Integer Overflow in readLength

Finding ID: `NPS-5675D7E4EBDD`

File: `openpgp/packet/packet.go:36`

In readLength, for the case buf[0] >= 224 && buf[0] < 255, length is computed as int64(1) << (buf[0] & 0x1f). Since buf[0] & 0x1f can be up to 31, and int64 is 64-bit, 1 << 31 is 2147483648, which fits. However, if the shift is larger than 63, it would overflow, but the mask limits to 31. The partial length feature can lead to large memory usage if not properly bounded, but the reader handles it in chunks. Not a direct overflow, but worth noting.

### [low] Potential Panic on Invalid Input (Denial of Service)

Finding ID: `NPS-07BEC8637BF5`

File: `openpgp/packet/packet.go:453`

In readMPI, the bitLength is read as a uint16 and then numBytes is computed as (int(bitLength)+7)/8. If bitLength is very large (e.g., 65535), numBytes becomes 8192, leading to a large allocation. An attacker could craft a packet that causes excessive memory allocation, potentially leading to a denial of service. Additionally, if readFull fails on the MPI bytes, the function returns an error, but the large allocation still occurs.

### [low] Unvalidated Length Leading to Large Allocations

Finding ID: `NPS-27A202B9DC50`

File: `openpgp/packet/packet.go:453`

In readMPI, the bit length is used to allocate a byte slice without a reasonable upper bound. An attacker could provide a bitLength of 65535, causing an allocation of ~8KB, which is not huge but could be repeated to cause memory exhaustion. Similarly, other packet parsing might allocate based on untrusted lengths.

### [low] Weak hash algorithm (SHA-1 for fingerprint)

Finding ID: `NPS-D770DB80E730`

File: `openpgp/packet/public_key.go:272`

The code uses SHA-1 to compute OpenPGP key fingerprints. SHA-1 is cryptographically weak and deprecated, but this is required by RFC 4880 for OpenPGP v4 keys and does not indicate malicious behavior.

### [low] Potential unhandled panic on unknown public key algorithm

Finding ID: `NPS-86E0BAFEB866`

File: `openpgp/packet/public_key.go:367`

Several methods (SerializeSignaturePrefix, Serialize, VerifySignatureV3) panic on unknown public key algorithms. This could crash an application if malformed data is processed, but it is a robustness issue, not a malicious pattern.

### [low] Missing type assertion checks

Finding ID: `NPS-A0491A7BC732`

File: `openpgp/packet/public_key.go:449`

In VerifySignature and VerifySignatureV3, type assertions like pk.PublicKey.(*rsa.PublicKey) are performed without the comma-ok idiom in some branches, which could panic on unexpected input. Again, a robustness concern rather than malicious code.

### [low] Potential integer overflow in length calculations

Finding ID: `NPS-6B5417AA5240`

File: `openpgp/packet/signature.go:97`

In the parse function, `l := 6 + hashedSubpacketsLength` and later `trailer[2] = uint8(l >> 24)` etc. Since hashedSubpacketsLength is a 16-bit value (max 65535), l fits in 32 bits, so no immediate overflow. However, in `serializeSubpackets` and `subpacketsLength`, integer arithmetic on lengths is done without overflow checks. While not directly exploitable here, it's a pattern that could lead to vulnerabilities if code evolves.

### [low] Improper input validation

Finding ID: `NPS-41E26D34D4AD`

File: `openpgp/packet/signature.go:185`

In `parseSignatureSubpacket`, for the `creationTimeSubpacket` case, there is a check for `len(subpacket) != 4`, but the code does not validate that the creation time is within a reasonable range (e.g., not in the far future or past). This could lead to logic errors or denial-of-service in downstream applications (e.g., time-based checks).

### [low] Non-constant-time comparison / timing side channel

Finding ID: `NPS-4E0FFEDB681C`

File: `openpgp/s2k/s2k.go`

The Salted and Iterated functions process input based on length and use loops that could leak timing information about the passphrase or salt length, though this is inherent to the S2K design and not an introduced backdoor.

### [low] Init-time global state construction

Finding ID: `NPS-7078462F0E03`

File: `otr/otr.go:132`

An init() function parses large hardcoded big integer constants (DH group parameters p, q, g) at import time. This is benign but worth noting as import-time behavior.

### [low] User-provided entropy override

Finding ID: `NPS-138BCC701B5D`

File: `otr/otr.go:199`

The Conversation.Rand field allows callers to override the entropy source. If callers supply weak/predictable randomness, DH private keys and AES-CTR nonces become predictable. This is by design but is a security footgun.

### [low] Panic on random source failure

Finding ID: `NPS-1AC860ACC473`

File: `otr/otr.go:206`

randMPI and other functions panic if the random source (crypto/rand by default) fails, rather than returning an error. If a caller overrides Rand with a malicious/weak reader, cryptographic material could be compromised. This is a robustness/security concern, not malicious code.

### [low] Resource management

Finding ID: `NPS-5E5DDF2BB24C`

File: `ssh/agent/forward.go:40`

In ForwardToAgent and ForwardToRemote, goroutines are spawned without limiting concurrency. While not directly malicious, this could lead to resource exhaustion if many channels are opened.

### [low] Potential denial of service

Finding ID: `NPS-85553F51017D`

File: `ssh/agent/forward.go:45`

The code uses io.Copy to discard stderr in separate goroutines without any timeout or limit. An attacker could potentially cause resource exhaustion by opening many channels.

### [low] Unix socket connection

Finding ID: `NPS-8F52B6129447`

File: `ssh/agent/forward.go:83`

ForwardToRemote and forwardUnixSocket connect to a Unix socket specified by the caller. If the address is attacker-controlled, it could lead to connection to malicious sockets or privilege escalation. However, the function requires the caller to provide the address, so the risk depends on usage.

### [low] Insecure cryptographic algorithms

Finding ID: `NPS-563551EA0D2F`

File: `ssh/kex.go:622`

The code registers legacy/insecure key exchange algorithms such as diffie-hellman-group1-sha1 (oakleyGroup2), diffie-hellman-group14-sha1, and diffie-hellman-group-exchange-sha1. These use SHA-1 and weak DH groups, which are cryptographically deprecated. However, they are only included when FIPS mode is disabled and are explicitly prefixed as 'InsecureKeyExchange...', indicating this is intentional for backward compatibility rather than a malicious pattern.

### [low] PRNG seed predictability

Finding ID: `NPS-2104A53906B4`

File: `ssh/tcpip.go:60`

portRandomizer uses math/rand seeded with time.Now().UnixNano() for the OpenSSH auto-port workaround. This is a weak randomness source, but it is only used to pick an arbitrary available port for a workaround, not for security-sensitive values like keys, tokens, or nonces. It is not a malicious pattern.

### [low] Build-time Code Execution

Finding ID: `NPS-AF571AEBCC6A`

File: `x509roots/gen_fallback_bundle.go:7`

The file has a //go:build generate constraint and //go:generate directive, meaning it only runs during explicit code generation, not at import or normal build time. No init() functions or top-level code that executes on import. This is a standard Go code generation pattern.

### [low] Network Request

Finding ID: `NPS-A54BBD2C7129`

File: `x509roots/gen_fallback_bundle.go:57`

Fetches certdata.txt from a hardcoded Mozilla URL (https://hg.mozilla.org/mozilla-central/raw-file/tip/security/nss/lib/ckfw/builtins/certdata.txt). This is expected for a certificate bundle generator and the URL is configurable via flag. No data is exfiltrated; the request is a standard HTTPS GET with proper Content-Type validation.

### [low] File System Write

Finding ID: `NPS-D636F1EF424E`

File: `x509roots/gen_fallback_bundle.go:145`

Writes generated Go source and DER certificate bundle to paths specified by flags (defaults: fallback/bundle/bundle.go and fallback/bundle/bundle.der). This is the intended purpose of the generator and does not operate outside package scope without explicit user-provided paths.

## Files reviewed

- `openpgp/read.go` (critical): The openpgp package is deprecated and unsafe by design, with multiple security weaknesses that can lead to message forgery, integrity bypass, and denial-of-service, making it critical for any application to avoid.
- `acme/internal/acmeprobe/prober.go` (medium): The acme/internal/acmeprobe/prober.go file implements a legitimate ACME CA test prober; the only notable risks are an intentional but powerful exec-based DNS hook and a user-specified server bind address, neither of which indicates malicious intent.
- `openpgp/elgamal/elgamal.go` (medium): The file is the legitimate Go standard-library ElGamal package with no malicious intent, but it ships deprecated, explicitly side-channel-vulnerable cryptography that constitutes a security warning for consumers.
- `openpgp/packet/packet.go` (medium): The code implements OpenPGP packet parsing and is explicitly deprecated with known security issues, uses weak cryptographic algorithms, and has minor error handling and resource allocation concerns, but no active malicious patterns were detected.
- `openpgp/packet/public_key_v3.go` (medium): Legitimate Go standard library OpenPGP v3 key handling code with expected legacy weak crypto (MD5 fingerprints, deprecated V3 keys) but no malicious patterns such as exfiltration, backdoors, or code execution.
- `openpgp/packet/signature.go` (medium): The code appears to be a legitimate implementation of OpenPGP signature parsing and signing, but contains several robustness and input validation issues that could lead to denial-of-service or incorrect parsing, though no malicious patterns were detected.
- `openpgp/s2k/s2k.go` (medium): The code contains no malicious patterns, but uses deprecated cryptographic primitives with weak defaults and is explicitly unmaintained, posing a security risk if used in production.
- `otr/otr.go` (medium): No malicious patterns (exfiltration, backdoors, install hooks, shell execution, obfuscation) were detected; the code is a standard Go OTR implementation with deprecated cryptographic primitives (DSA-1024/SHA-1) inherent to the OTRv2 protocol.
- `ssh/agent/forward.go` (medium): The code implements legitimate SSH agent forwarding functionality but includes patterns that could be risky if misused, such as connecting to arbitrary Unix sockets and unlimited goroutine spawning.
- `acme/acme.go` (safe): This is a legitimate Go ACME client library from the Go standard library's x/crypto/acme package with no malicious patterns detected.
- `acme/autocert/autocert.go` (safe): No malicious patterns detected; this is the standard Go autocert package implementing ACME certificate management with expected cryptographic and network operations.
- `acme/autocert/cache.go` (safe): This is the standard Go autocert DirCache implementation with well-understood filesystem operations, path sanitization via filepath.Clean, and no malicious patterns such as exfiltration, process execution, or credential harvesting.
- `acme/autocert/internal/acmetest/ca.go` (safe): This is a legitimate ACME test server used exclusively for Go package testing, with no malicious patterns, data exfiltration, or suspicious behavior detected.
- `acme/autocert/listener.go` (safe): No malicious patterns detected
- `acme/autocert/renewal.go` (safe): No malicious patterns detected; the code is a standard certificate renewal implementation from Go's acme/autocert package with no exfiltration, credential harvesting, obfuscation, or backdoor behavior.
- `acme/http.go` (safe): The code is a legitimate Go ACME client HTTP implementation with standard retry logic, nonce handling, and request signing; no malicious patterns detected.
- `acme/jws.go` (safe): No malicious patterns detected; the code is a legitimate ACME JWS implementation with standard cryptographic operations and no obfuscation, exfiltration, or dynamic execution.
- `acme/rfc8555.go` (safe): This is a standard, legitimate Go implementation of the ACME protocol (RFC 8555) from the golang.org/x/crypto/acme package with no malicious patterns detected.
- `acme/types.go` (safe): Cleared by Jev triage; no further analysis needed
- `argon2/argon2.go` (safe): Cleared by Jev triage; no further analysis needed
- `argon2/blake2b.go` (safe): Cleared by Jev triage; no further analysis needed
- `argon2/blamka_amd64.go` (safe): No malicious patterns detected; this is a legitimate Go assembly helper file for Argon2's Blamka permutation with CPU feature detection and no network, filesystem, or execution abuse.
- `argon2/blamka_generic.go` (safe): Cleared by Jev triage; no further analysis needed
- `argon2/blamka_ref.go` (safe): Cleared by Jev triage; no further analysis needed
- `bcrypt/base64.go` (safe): Cleared by Jev triage; no further analysis needed
- `bcrypt/bcrypt.go` (safe): Cleared by Jev triage; no further analysis needed
- `blake2b/blake2b.go` (safe): Cleared by Jev triage; no further analysis needed
- `blake2b/blake2bAVX2_amd64.go` (safe): No malicious patterns detected
- `blake2b/blake2b_generic.go` (safe): Cleared by Jev triage; no further analysis needed
- `blake2b/blake2b_ref.go` (safe): Cleared by Jev triage; no further analysis needed
- `blake2b/blake2x.go` (safe): Cleared by Jev triage; no further analysis needed
- `blake2b/register.go` (safe): No malicious patterns detected; the code only registers standard BLAKE2b hash implementations with Go's crypto package at init time.
- `blake2s/blake2s.go` (safe): No malicious patterns detected
- `blake2s/blake2s_386.go` (safe): Cleared by Jev triage; no further analysis needed
- `blake2s/blake2s_amd64.go` (safe): Cleared by Jev triage; no further analysis needed
- `blake2s/blake2s_generic.go` (safe): Cleared by Jev triage; no further analysis needed
- `blake2s/blake2s_ref.go` (safe): Cleared by Jev triage; no further analysis needed
- `blake2s/blake2x.go` (safe): Cleared by Jev triage; no further analysis needed
- `blowfish/block.go` (safe): Cleared by Jev triage; no further analysis needed
- `blowfish/cipher.go` (safe): Cleared by Jev triage; no further analysis needed
- `blowfish/const.go` (safe): Cleared by Jev triage; no further analysis needed
- `bn256/bn256.go` (safe): No malicious patterns detected; the code is a deprecated but legitimate Go cryptographic library implementation.
- `bn256/constants.go` (safe): Cleared by Jev triage; no further analysis needed
- `bn256/curve.go` (safe): Cleared by Jev triage; no further analysis needed
- `bn256/gfp12.go` (safe): Cleared by Jev triage; no further analysis needed
- `bn256/gfp2.go` (safe): Cleared by Jev triage; no further analysis needed
- `bn256/gfp6.go` (safe): Cleared by Jev triage; no further analysis needed
- `bn256/optate.go` (safe): Cleared by Jev triage; no further analysis needed
- `bn256/twist.go` (safe): Cleared by Jev triage; no further analysis needed
- `cast5/cast5.go` (safe): Cleared by Jev triage; no further analysis needed
- `chacha20/chacha_arm64.go` (safe): Cleared by Jev triage; no further analysis needed
- `chacha20/chacha_generic.go` (safe): Cleared by Jev triage; no further analysis needed
- `chacha20/chacha_noasm.go` (safe): Cleared by Jev triage; no further analysis needed
- `chacha20/chacha_ppc64x.go` (safe): Cleared by Jev triage; no further analysis needed
- `chacha20/chacha_s390x.go` (safe): Cleared by Jev triage; no further analysis needed
- `chacha20/xor.go` (safe): Cleared by Jev triage; no further analysis needed
- `chacha20poly1305/chacha20poly1305.go` (safe): Cleared by Jev triage; no further analysis needed
- `chacha20poly1305/chacha20poly1305_amd64.go` (safe): Cleared by Jev triage; no further analysis needed
- `chacha20poly1305/chacha20poly1305_generic.go` (safe): Cleared by Jev triage; no further analysis needed
- `chacha20poly1305/chacha20poly1305_noasm.go` (safe): Cleared by Jev triage; no further analysis needed
- `chacha20poly1305/fips140only_compat.go` (safe): Cleared by Jev triage; no further analysis needed
- `chacha20poly1305/fips140only_go1.26.go` (safe): Cleared by Jev triage; no further analysis needed
- `chacha20poly1305/xchacha20poly1305.go` (safe): Cleared by Jev triage; no further analysis needed
- `cryptobyte/asn1.go` (safe): No malicious patterns detected
- `cryptobyte/asn1/asn1.go` (safe): Cleared by Jev triage; no further analysis needed
- `cryptobyte/builder.go` (safe): Cleared by Jev triage; no further analysis needed
- `cryptobyte/string.go` (safe): Cleared by Jev triage; no further analysis needed
- `curve25519/curve25519.go` (safe): No malicious patterns detected; the code is a standard, frozen Go wrapper for X25519 using crypto/ecdh with no network, filesystem, process, or obfuscation concerns.
- `ed25519/ed25519.go` (safe): This is a standard, frozen Go wrapper around crypto/ed25519 with no malicious patterns; it contains only type aliases and thin delegating functions to the standard library.
- `hkdf/hkdf.go` (safe): No malicious patterns detected; the code is a standard, legitimate implementation of HKDF from the Go standard library ecosystem.
- `internal/alias/alias.go` (safe): No malicious patterns detected; the code is a standard memory aliasing utility using unsafe pointers for overlap checks without any exfiltration, execution, or persistence behavior.
- `internal/alias/alias_purego.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/poly1305/mac_noasm.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/poly1305/poly1305.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/poly1305/sum_asm.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/poly1305/sum_generic.go` (safe): No malicious patterns detected; code is a legitimate Go Poly1305 cryptographic implementation with only standard library usage.
- `internal/poly1305/sum_s390x.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/testenv/exec.go` (safe): The code is a legitimate test helper for managing subprocesses with timeouts and cleanup; it contains no malicious patterns despite using process spawning and environment variable reads.
- `internal/testenv/testenv_notunix.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/testenv/testenv_unix.go` (safe): No malicious patterns detected
- `md4/md4.go` (safe): The code implements the standard MD4 hash algorithm as found in Go's crypto packages, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or network activity.
- `md4/md4block.go` (safe): Cleared by Jev triage; no further analysis needed
- `nacl/auth/auth.go` (safe): Cleared by Jev triage; no further analysis needed
- `nacl/box/box.go` (safe): This is the standard Go x/crypto/nacl/box implementation providing public-key authenticated encryption with no malicious patterns detected.
- `nacl/secretbox/secretbox.go` (safe): Cleared by Jev triage; no further analysis needed
- `nacl/sign/sign.go` (safe): No malicious patterns detected; the code is a straightforward wrapper around crypto/ed25519 from the Go standard library with no network, filesystem, process, or dynamic code execution activity.
- `ocsp/ocsp.go` (safe): No malicious patterns detected; the code is the standard Go OCSP package with only cryptographic parsing and signing operations.
- `openpgp/armor/armor.go` (safe): No malicious patterns detected; the code is a legitimate, standard library implementation of OpenPGP ASCII Armor decoding with no exfiltration, credential harvesting, or other suspicious behavior.
- `openpgp/armor/encode.go` (safe): Cleared by Jev triage; no further analysis needed
- `openpgp/canonical_text.go` (safe): Cleared by Jev triage; no further analysis needed
- `openpgp/clearsign/clearsign.go` (safe): This is the standard Go clearsign package source, marked deprecated for known design weaknesses but containing no malicious patterns such as exfiltration, credential harvesting, obfuscation, process spawning, or network backdoors.
- `openpgp/errors/errors.go` (safe): Cleared by Jev triage; no further analysis needed
- `openpgp/keys.go` (safe): No malicious patterns detected
- `openpgp/packet/compressed.go` (safe): No malicious patterns detected in this standard OpenPGP compressed packet implementation; it performs only in-memory compression/decompression using Go standard libraries without network, filesystem, process, or dynamic code execution.
- `openpgp/packet/config.go` (safe): Cleared by Jev triage; no further analysis needed
- `openpgp/packet/encrypted_key.go` (safe): No malicious patterns detected; the code is a standard OpenPGP encrypted key packet implementation from the Go standard library with no data exfiltration, credential harvesting, obfuscation, or backdoor behavior.
- `openpgp/packet/literal.go` (safe): No malicious patterns detected
- `openpgp/packet/ocfb.go` (safe): Cleared by Jev triage; no further analysis needed
- `openpgp/packet/one_pass_signature.go` (safe): Cleared by Jev triage; no further analysis needed
- `openpgp/packet/opaque.go` (safe): No malicious patterns detected; this is a legitimate OpenPGP opaque packet parsing implementation from the official Go crypto library with no network, filesystem, process execution, or obfuscation behaviors.
- `openpgp/packet/private_key.go` (safe): No malicious patterns detected in the OpenPGP private key parsing code; it implements standard cryptographic key handling per RFC 4880 without exfiltration, backdoors, or suspicious behavior.
- `openpgp/packet/public_key.go` (safe): This is a standard OpenPGP public key parsing module from the Go x/crypto library; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, network activity, or code execution were found.
- `openpgp/packet/reader.go` (safe): No malicious patterns detected; the code is a standard OpenPGP packet reader with a recursion limit to prevent CVE-2013-4402.
- `openpgp/packet/signature_v3.go` (safe): No malicious patterns detected; the code is a standard OpenPGP v3 signature parser/serializer with no exfiltration, credential harvesting, obfuscation, or command execution.
- `openpgp/packet/symmetric_key_encrypted.go` (safe): No malicious patterns detected; the code is a standard OpenPGP symmetric key encryption packet implementation from golang.org/x/crypto/openpgp.
- `openpgp/packet/symmetrically_encrypted.go` (safe): This is a legitimate Go standard library implementation of OpenPGP symmetrically encrypted packets with MDC integrity checking; no malicious patterns detected.
- `openpgp/packet/userattribute.go` (safe): Cleared by Jev triage; no further analysis needed
- `openpgp/packet/userid.go` (safe): Cleared by Jev triage; no further analysis needed
- `openpgp/write.go` (safe): No malicious patterns detected; the code is a legitimate Go OpenPGP implementation from the official golang.org/x/crypto library.
- `otr/smp.go` (safe): No malicious patterns detected; the code implements the OTR Socialist Millionaires Protocol using standard cryptographic primitives without any exfiltration, backdoor, or suspicious behavior.
- `pbkdf2/pbkdf2.go` (safe): Cleared by Jev triage; no further analysis needed
- `pkcs12/bmp-string.go` (safe): Cleared by Jev triage; no further analysis needed
- `pkcs12/crypto.go` (safe): Cleared by Jev triage; no further analysis needed
- `pkcs12/errors.go` (safe): Cleared by Jev triage; no further analysis needed
- `pkcs12/internal/rc2/rc2.go` (safe): Cleared by Jev triage; no further analysis needed
- `pkcs12/mac.go` (safe): This is standard PKCS#12 MAC verification code with a sensible iteration limit and no malicious patterns detected.
- `pkcs12/pbkdf.go` (safe): Cleared by Jev triage; no further analysis needed
- `pkcs12/pkcs12.go` (safe): No malicious patterns detected; the file is a standard Go implementation of PKCS#12 decoding from the standard library with no exfiltration, code execution, network, or filesystem abuse.
- `pkcs12/safebags.go` (safe): No malicious patterns detected
- `poly1305/poly1305_compat.go` (safe): This is a legitimate, deprecated compatibility wrapper around Go's standard golang.org/x/crypto/internal/poly1305 package with no malicious patterns.
- `ripemd160/ripemd160.go` (safe): No malicious patterns detected; the file is a standard, unmodified implementation of the deprecated RIPEMD-160 hash algorithm.
- `ripemd160/ripemd160block.go` (safe): Cleared by Jev triage; no further analysis needed
- `salsa20/salsa/hsalsa20.go` (safe): Cleared by Jev triage; no further analysis needed
- `salsa20/salsa/salsa208.go` (safe): Cleared by Jev triage; no further analysis needed
- `salsa20/salsa/salsa20_amd64.go` (safe): Cleared by Jev triage; no further analysis needed
- `salsa20/salsa/salsa20_noasm.go` (safe): Cleared by Jev triage; no further analysis needed
- `salsa20/salsa/salsa20_ref.go` (safe): Cleared by Jev triage; no further analysis needed
- `salsa20/salsa20.go` (safe): Cleared by Jev triage; no further analysis needed
- `scrypt/scrypt.go` (safe): Cleared by Jev triage; no further analysis needed
- `sha3/hashes.go` (safe): Cleared by Jev triage; no further analysis needed
- `sha3/legacy_hash.go` (safe): No malicious patterns detected; the file is a legitimate Keccak hash implementation with standard cryptographic code and no exfiltration, persistence, or obfuscation.
- `sha3/legacy_keccakf.go` (safe): Cleared by Jev triage; no further analysis needed
- `sha3/shake.go` (safe): Cleared by Jev triage; no further analysis needed
- `ssh/agent/client.go` (safe): No malicious patterns detected; this is the standard Go ssh-agent client implementation with legitimate protocol handling and no exfiltration, code execution, or credential harvesting behavior.
- `ssh/agent/keyring.go` (safe): No malicious patterns detected in the SSH agent keyring implementation.
- `ssh/agent/server.go` (safe): No malicious patterns detected; this is the standard Go SSH agent server implementation with appropriate input validation and resource limits.
- `ssh/buffer.go` (safe): Cleared by Jev triage; no further analysis needed
- `ssh/certs.go` (safe): This is a legitimate Go crypto/SSH certificate handling file from the golang.org/x/crypto/ssh package with no malicious patterns detected.
- `ssh/channel.go` (safe): This is the standard Go x/crypto/ssh channel implementation with normal flow-control, packet handling, and request management; no malicious patterns, exfiltration, credential harvesting, dynamic execution, or install-time behavior were detected.
- `ssh/cipher.go` (safe): This is the standard Go x/crypto/ssh cipher implementation with no malicious patterns; it contains only legitimate SSH encryption/decryption logic, including intentionally insecure ciphers (RC4, CBC, 3DES) that are clearly marked as insecure and excluded from default configuration.
- `ssh/client.go` (safe): No malicious patterns detected; this is legitimate Go SSH client code from the official golang.org/x/crypto/ssh package with no exfiltration, credential harvesting, obfuscation, or dynamic code execution.
- `ssh/client_auth.go` (safe): This is a legitimate, unmodified portion of the Go standard library's x/crypto/ssh package implementing SSH client authentication; no malicious patterns, exfiltration, credential harvesting, obfuscation, or unauthorized execution were detected.
- `ssh/common.go` (safe): This is the standard Go x/crypto/ssh common.go file containing algorithm definitions and helpers with no malicious patterns detected.
- `ssh/connection.go` (safe): No malicious patterns detected; this is standard Go SSH connection interface and metadata code from the golang.org/x/crypto/ssh package with no exfiltration, credential harvesting, obfuscation, process spawning, or suspicious network activity.
- `ssh/control.go` (safe): No malicious patterns detected; the code implements a legitimate SSH ControlMaster proxy handshake and transport without any exfiltration, credential harvesting, obfuscation, or backdoor behavior.
- `ssh/doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `ssh/handshake.go` (safe): No malicious patterns detected; the code is a legitimate SSH handshake implementation from the Go standard library's x/crypto/ssh package.
- `ssh/internal/bcrypt_pbkdf/bcrypt_pbkdf.go` (safe): Cleared by Jev triage; no further analysis needed
- `ssh/kex.go` (safe): This is a legitimate Go SSH key exchange implementation with no evidence of malicious activity; only standard legacy-cipher backward-compatibility concerns are present.
- `ssh/keys.go` (safe): This is the standard golang.org/x/crypto/ssh keys implementation handling public/private key parsing, marshaling, signing, and verification with no malicious patterns such as exfiltration, credential harvesting, obfuscated execution, or process spawning.
- `ssh/knownhosts/knownhosts.go` (safe): This is the legitimate golang.org/x/crypto/ssh/knownhosts package; no malicious patterns such as exfiltration, credential harvesting, obfuscation, shells, or install-time execution were found.
- `ssh/mac.go` (safe): No malicious patterns detected
- `ssh/messages.go` (safe): This is the standard Go crypto/ssh messages.go file implementing SSH wire format marshaling/unmarshaling with no malicious patterns, network exfiltration, credential harvesting, or code execution.
- `ssh/mlkem.go` (safe): The file implements a standard hybrid post-quantum key exchange (ML-KEM768 with Curve25519) from the official Go SSH package, with no malicious patterns detected.
- `ssh/mux.go` (safe): The file is a standard part of the Go SSH library (ssh/mux.go) containing only legitimate channel multiplexing logic with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, shell commands, or network abuse.
- `ssh/server.go` (safe): This is the standard Go x/crypto/ssh server implementation, and no malicious patterns such as exfiltration, credential harvesting, obfuscation, backdoors, or install-time execution were detected.
- `ssh/session.go` (safe): No malicious patterns detected
- `ssh/ssh_gss.go` (safe): The code is part of Go's SSH library implementing GSSAPI/Kerberos authentication interfaces and contains only standard, benign initialization and parsing logic with no malicious patterns.
- `ssh/streamlocal.go` (safe): No malicious patterns detected
- `ssh/tcpip.go` (safe): This is the standard Go x/crypto/ssh tcpip.go implementation for SSH port forwarding; no malicious patterns, exfiltration, backdoors, or process execution were detected.
- `ssh/terminal/terminal.go` (safe): No malicious patterns detected; the file is a thin deprecated wrapper delegating to golang.org/x/term with no network, filesystem, process, or dynamic execution behavior.
- `ssh/testdata/doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `ssh/testdata/keys.go` (safe): Cleared by Jev triage; no further analysis needed
- `ssh/transport.go` (safe): This is a legitimate Go SSH transport implementation from the official Go crypto library with no malicious patterns detected.
- `tea/cipher.go` (safe): Cleared by Jev triage; no further analysis needed
- `twofish/twofish.go` (safe): Cleared by Jev triage; no further analysis needed
- `x509roots/gen_fallback_bundle.go` (safe): This is a legitimate Go code generator for fallback certificate bundles that fetches and parses Mozilla NSS certdata; no malicious patterns detected.
- `x509roots/nss/parser.go` (safe): No malicious patterns detected; the code is a legitimate NSS certdata.txt parser with no network, credential, or code-execution behavior.
- `xtea/block.go` (safe): Cleared by Jev triage; no further analysis needed
- `xtea/cipher.go` (safe): Cleared by Jev triage; no further analysis needed
- `xts/xts.go` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
