Togoder security

Go package security report

golang.org/x/crypto@v0.57.0 security report

Critical: dangerous or likely malicious code found.

Critical risk Version v0.57.0 Files reviewed 171 Size 1.3 MB Scanned

Summary

Togoder Security scanned the Go package golang.org/x/crypto@v0.57.0 on Oct 5, 2026. An AI review of 171 source files produced 1 critical, 3 high, 18 medium, 28 low severity findings. At least one finding describes dangerous behavior such as code that runs at install time, credential access or data exfiltration. Do not install this version until you have reviewed the findings below.

1
critical
3
high
18
medium
28
low

Findings 50

critical

dangerous_default_deprecation

NPS-C137C547738E

The package documentation explicitly states the package is 'unsafe by design' and has 'numerous known security issues' and 'should not be used'. This is a critical security concern for any application relying on it, as it may contain unpatched vulnerabilities leading to message forgery, decryption failures, or other cryptographic weaknesses.

openpgp/read.go:8
high

insufficient_signature_verification

NPS-5A5ECBAB5556

The ReadMessage function only sets up signature verification if the signer key is present in the keyring (md.SignedBy != nil). If the signer's key is not found, the signature is never checked, and the data is treated as unsigned. This can allow forged messages or tampering, as attackers could omit the signature or use a key not in the keyring.

openpgp/read.go:222
high

mdc_check_timing

NPS-94D3D7DBD1BF

The integrity check (MDC) is only performed when the UnverifiedBody is read to EOF. If the caller does not fully consume the body, the check is skipped. This can lead to acceptance of tampered messages if the application does not adhere to the documented requirement to read until EOF. Applications may mistakenly trust unverified data.

openpgp/read.go:316
high

Deprecated and unmaintained cryptography

NPS-A03368E29BB0

The package is explicitly documented as unsafe by design, has known security issues, and is not maintained, meaning vulnerabilities will not be patched.

openpgp/s2k/s2k.go:9
medium

Command execution with user-controlled script

NPS-A64203707463

The runDNS01 function executes an arbitrary script specified via the -s command-line flag using exec.CommandContext. The script is invoked with the challenge name and token as arguments. While this is intentional for the ACME prober's DNS-01 challenge provisioning, it represents a process-spawning capability driven by external input. If an attacker can control the -s flag or influence its value (e.g., via a wrapper or CI harness), arbitrary commands could be executed with the privileges of the prober.

acme/internal/acmeprobe/prober.go:320
medium

Insecure cryptographic implementation

NPS-BB0E27FFBB9C

The package's own documentation explicitly states: 'this package doesn't protect against side-channel attacks' and it embeds PKCS#1 v1.5 padding which the code itself acknowledges creates a padding oracle vulnerable to Bleichenbacher-style adaptive chosen ciphertext attacks. While not overtly malicious, shipping a known-insecure crypto primitive that may be silently used by downstream consumers poses a real security risk to applications relying on it.

openpgp/elgamal/elgamal.go
medium

Deprecated and Unsafe Cryptography

NPS-6452FBEC3A89

The package itself is marked as Deprecated and states it 'is unsafe by design, and has numerous known security issues. It is not maintained, and should not be used.' This is a significant security concern as it may contain known vulnerabilities (e.g., CVE-2023-... for Go OpenPGP) and lacks security updates.

openpgp/packet/packet.go:6
medium

Insecure Use of crypto/des

NPS-87B888E46E5B

The package imports crypto/des which is considered insecure for modern use, as DES and 3DES are deprecated. This aligns with the package's deprecated status and known issues.

openpgp/packet/packet.go:26
medium

Weak Cryptography Algorithms

NPS-8776DA6C7EB0

The code supports weak ciphers such as Cipher3DES and CipherCAST5, and deprecated public key algorithms like PubKeyAlgoRSAEncryptOnly and PubKeyAlgoRSASignOnly. Use of these algorithms is discouraged as they may be vulnerable to attacks.

openpgp/packet/packet.go:351
medium

Lack of Error Handling in Cipher Initialization

NPS-E43F34652C92

The new method for CipherFunction ignores errors from des.NewTripleDESCipher, cast5.NewCipher, and aes.NewCipher. If an invalid key length is provided (e.g., due to a malformed packet), the returned block cipher may be nil or incomplete, which could lead to a panic or unpredictable behavior when used later.

openpgp/packet/packet.go:430
medium

Deprecated/insecure key version support

NPS-F5D655B7935D

Implements support for V3 OpenPGP public keys, which are explicitly documented as less secure and should not be used for signing or encrypting. The code allows parsing and signature verification of deprecated V3 keys, which could enable downgrade attacks if callers don't enforce version restrictions.

openpgp/packet/public_key_v3.go:24
medium

Weak cryptographic algorithm

NPS-0FD5AAFE1720

Uses MD5 for fingerprint computation in setFingerPrintAndKeyId. MD5 is cryptographically broken and unsuitable for security-sensitive operations, though this is mandated by RFC 4880 for v3 key fingerprints. This is a legacy compatibility requirement, not malicious, but represents a security weakness.

openpgp/packet/public_key_v3.go:82
medium

Unvalidated RSA key parameters

NPS-7DBA4348AF51

In parseRSA, the RSA modulus and exponent are parsed from network input with minimal validation. While there is a check that the modulus is at least 8 bytes and the exponent is at most 3 bytes, there is no check on minimum RSA modulus size (bit length), allowing potentially very weak RSA keys (e.g., tiny moduli) to be accepted.

openpgp/packet/public_key_v3.go:95
medium

Unbounded memory allocation

NPS-BBD2F866F2A2

The parse function reads a 2-byte length for hashed subpackets (hashedSubpacketsLength) and allocates a buffer sig.HashSuffix of size l+6 where l = 6 + hashedSubpacketsLength. An attacker can specify a large length (up to 65535) causing a relatively large allocation. More critically, later it reads a 2-byte length for unhashed subpackets and allocates make([]byte, unhashedSubpacketsLength) without any upper bound check. This can lead to excessive memory allocation (up to 64KB per signature packet), which could be exploited for memory exhaustion in a denial-of-service attack.

openpgp/packet/signature.go:97
medium

Potential panic on untrusted input

NPS-AB6301D7DFB7

The parse function contains a panic("unreachable") in the default case of the public key algorithm switch. Although the algorithm is validated earlier, if an attacker can control the input in a way that bypasses the earlier validation (e.g., via a crafted packet that causes the switch cases to mismatch), it could lead to a denial-of-service (panic). This is a robustness issue in a security-critical parser.

openpgp/packet/signature.go:134
medium

Error handling inconsistency

NPS-3F0A6068859B

In parseSignatureSubpacket, for certain subpacket types (e.g., signatureExpirationSubpacket, keyExpirationSubpacket, prefSymmetricAlgosSubpacket, etc.), if !isHashed, the function returns early with return (nil error, nil rest). This effectively skips parsing the subpacket and returns rest as nil. This could cause the caller to stop processing the remaining subpackets prematurely, potentially leading to incorrect parsing or bypassing of subsequent subpackets. An attacker could craft a packet to exploit this to hide malicious data or cause misinterpretation.

openpgp/packet/signature.go:202
medium

Use of unsafe type assertions

NPS-58A6E245AB5D

In the Sign function, there are type assertions like priv.PrivateKey.(crypto.Signer) without checking the ok boolean. If the private key is not of the expected type, this will panic. While the caller might ensure the correct type, this is a robustness issue that could lead to a crash if the API is misused. In a security context, unexpected panics can be exploited for denial-of-service.

openpgp/packet/signature.go:374
medium

infinite_prompt_loop

NPS-F7D5FE2BC409

The PromptFunction is called in a loop that continues forever if the prompt returns a passphrase or key that is incorrect. This could lead to a denial-of-service or user frustration, as there is no limit on retries. In automated systems, this could hang indefinitely, potentially causing resource exhaustion.

openpgp/read.go:165
medium

panic_unreachable

NPS-3EF5239912F1

Several places contain panic statements that are supposedly unreachable but could be triggered by malicious input causing unexpected code paths. For example, in CheckDetachedSignature, a panic can occur if the loop exits without finding keys, but the condition is checked before the loop; however, if the keyring's KeysByIdUsage returns an empty slice, the subsequent code may panic. This could be exploited for denial-of-service.

openpgp/read.go:477
medium

Weak default cryptographic parameters

NPS-5E84C491C0D8

The package defaults to SHA1 and a low iteration count (65536) for key derivation when Config is nil, which is weak by modern standards and could enable brute-force attacks on derived keys.

openpgp/s2k/s2k.go:44
medium

Insecure cryptography (DSA 1024/160, SHA-1, deprecated protocol)

NPS-AB69D2306FCD

The package uses DSA with 1024-bit parameters (L1024N160) and SHA-1 for MACs, which are weak/deprecated. This is inherent to the OTRv2 protocol design and is documented as deprecated, but it constitutes a cryptographic weakness rather than a malicious pattern.

otr/otr.go
medium

Agent forwarding

NPS-FEA1F45359DE

The code implements SSH agent forwarding, which if misused can allow an attacker with access to the remote host to use the local SSH agent to authenticate to other systems. This is a legitimate feature but carries inherent security risks if not properly controlled.

ssh/agent/forward.go
low

Credential/account material generation and handling

NPS-E8F9EFD44DBE

The tool generates an ECDSA account key and CSR key, registers an ACME account, and then deactivates it. No exfiltration of credentials to third parties is present. However, the process handles private keys in memory and prints certificate details (serial, subject, leaf PEM) to logs, which could leak sensitive certificate metadata if logs are accessible.

acme/internal/acmeprobe/prober.go:130
low

Network server binding to user-specified address

NPS-FF9E50FFE801

The prober spins up HTTP/TLS servers on an address taken directly from the -a command-line flag (p.localAddr). Binding to user-controlled addresses (including potentially 0.0.0.0 or public interfaces) without validation could expose the challenge server beyond intended scopes. In the context of this tool, the user is expected to set this deliberately, but it is a potential misconfiguration risk.

acme/internal/acmeprobe/prober.go:250
low

Environment variable read

NPS-61B63EAE447E

Reads GO_TEST_TIMEOUT_SCALE environment variable to adjust timeout scaling. This is a benign test configuration variable, not credential or sensitive data harvesting.

internal/testenv/exec.go:37
low

Process spawning (os/exec)

NPS-1A5F603D77CE

The code uses os/exec to spawn subprocesses based on user-provided command and arguments. This is expected for a test helper library and is not malicious. The commands are explicitly provided by the caller (test code).

internal/testenv/exec.go:68
low

Reflection for compatibility

NPS-49AC3DAB1EEC

Uses reflection to conditionally set Cancel and WaitDelay fields on exec.Cmd for Go version compatibility. The reflected field names are hardcoded and legitimate (they are part of exec.Cmd).

internal/testenv/exec.go:82
low

Deprecated Cryptographic Algorithm

NPS-93A178B6A95E

MD4 is cryptographically broken and unsuitable for security purposes. The package itself documents this deprecation. This is a known weakness but not a malicious pattern.

md4/md4.go:7
low

Deprecated / abandoned dependency

NPS-B0B99EA7C7FF

The package and the parent golang.org/x/crypto/openpgp are explicitly deprecated, with known compatibility and security issues referenced (eprint.iacr.org/2021/923). Continued use introduces a supply-chain risk of relying on unmaintained security-critical code.

openpgp/elgamal/elgamal.go
low

Constant-time best effort weaknesses

NPS-A5C1E45F5D7B

Decrypt attempts constant-time comparison with subtle.ConstantTimeSelect/ByteEq, but iterating over variable-length big.Int.Bytes() output and slicing em[index+1:] leaks length information and does not fully defend the padding check, consistent with the package's own warning about side channels.

openpgp/elgamal/elgamal.go
low

Potential Integer Overflow in readLength

NPS-5675D7E4EBDD

In readLength, for the case buf[0] >= 224 && buf[0] < 255, length is computed as int64(1) << (buf[0] & 0x1f). Since buf[0] & 0x1f can be up to 31, and int64 is 64-bit, 1 << 31 is 2147483648, which fits. However, if the shift is larger than 63, it would overflow, but the mask limits to 31. The partial length feature can lead to large memory usage if not properly bounded, but the reader handles it in chunks. Not a direct overflow, but worth noting.

openpgp/packet/packet.go:36
low

Potential Panic on Invalid Input (Denial of Service)

NPS-07BEC8637BF5

In readMPI, the bitLength is read as a uint16 and then numBytes is computed as (int(bitLength)+7)/8. If bitLength is very large (e.g., 65535), numBytes becomes 8192, leading to a large allocation. An attacker could craft a packet that causes excessive memory allocation, potentially leading to a denial of service. Additionally, if readFull fails on the MPI bytes, the function returns an error, but the large allocation still occurs.

openpgp/packet/packet.go:453
low

Unvalidated Length Leading to Large Allocations

NPS-27A202B9DC50

In readMPI, the bit length is used to allocate a byte slice without a reasonable upper bound. An attacker could provide a bitLength of 65535, causing an allocation of ~8KB, which is not huge but could be repeated to cause memory exhaustion. Similarly, other packet parsing might allocate based on untrusted lengths.

openpgp/packet/packet.go:453
low

Weak hash algorithm (SHA-1 for fingerprint)

NPS-D770DB80E730

The code uses SHA-1 to compute OpenPGP key fingerprints. SHA-1 is cryptographically weak and deprecated, but this is required by RFC 4880 for OpenPGP v4 keys and does not indicate malicious behavior.

openpgp/packet/public_key.go:272
low

Potential unhandled panic on unknown public key algorithm

NPS-86E0BAFEB866

Several methods (SerializeSignaturePrefix, Serialize, VerifySignatureV3) panic on unknown public key algorithms. This could crash an application if malformed data is processed, but it is a robustness issue, not a malicious pattern.

openpgp/packet/public_key.go:367
low

Missing type assertion checks

NPS-A0491A7BC732

In VerifySignature and VerifySignatureV3, type assertions like pk.PublicKey.(*rsa.PublicKey) are performed without the comma-ok idiom in some branches, which could panic on unexpected input. Again, a robustness concern rather than malicious code.

openpgp/packet/public_key.go:449
low

Potential integer overflow in length calculations

NPS-6B5417AA5240

In the parse function, l := 6 + hashedSubpacketsLength and later trailer[2] = uint8(l >> 24) etc. Since hashedSubpacketsLength is a 16-bit value (max 65535), l fits in 32 bits, so no immediate overflow. However, in serializeSubpackets and subpacketsLength, integer arithmetic on lengths is done without overflow checks. While not directly exploitable here, it's a pattern that could lead to vulnerabilities if code evolves.

openpgp/packet/signature.go:97
low

Improper input validation

NPS-41E26D34D4AD

In parseSignatureSubpacket, for the creationTimeSubpacket case, there is a check for len(subpacket) != 4, but the code does not validate that the creation time is within a reasonable range (e.g., not in the far future or past). This could lead to logic errors or denial-of-service in downstream applications (e.g., time-based checks).

openpgp/packet/signature.go:185
low

Non-constant-time comparison / timing side channel

NPS-4E0FFEDB681C

The Salted and Iterated functions process input based on length and use loops that could leak timing information about the passphrase or salt length, though this is inherent to the S2K design and not an introduced backdoor.

openpgp/s2k/s2k.go
low

Init-time global state construction

NPS-7078462F0E03

An init() function parses large hardcoded big integer constants (DH group parameters p, q, g) at import time. This is benign but worth noting as import-time behavior.

otr/otr.go:132
low

User-provided entropy override

NPS-138BCC701B5D

The Conversation.Rand field allows callers to override the entropy source. If callers supply weak/predictable randomness, DH private keys and AES-CTR nonces become predictable. This is by design but is a security footgun.

otr/otr.go:199
low

Panic on random source failure

NPS-1AC860ACC473

randMPI and other functions panic if the random source (crypto/rand by default) fails, rather than returning an error. If a caller overrides Rand with a malicious/weak reader, cryptographic material could be compromised. This is a robustness/security concern, not malicious code.

otr/otr.go:206
low

Resource management

NPS-5E5DDF2BB24C

In ForwardToAgent and ForwardToRemote, goroutines are spawned without limiting concurrency. While not directly malicious, this could lead to resource exhaustion if many channels are opened.

ssh/agent/forward.go:40
low

Potential denial of service

NPS-85553F51017D

The code uses io.Copy to discard stderr in separate goroutines without any timeout or limit. An attacker could potentially cause resource exhaustion by opening many channels.

ssh/agent/forward.go:45
low

Unix socket connection

NPS-8F52B6129447

ForwardToRemote and forwardUnixSocket connect to a Unix socket specified by the caller. If the address is attacker-controlled, it could lead to connection to malicious sockets or privilege escalation. However, the function requires the caller to provide the address, so the risk depends on usage.

ssh/agent/forward.go:83
low

Insecure cryptographic algorithms

NPS-563551EA0D2F

The code registers legacy/insecure key exchange algorithms such as diffie-hellman-group1-sha1 (oakleyGroup2), diffie-hellman-group14-sha1, and diffie-hellman-group-exchange-sha1. These use SHA-1 and weak DH groups, which are cryptographically deprecated. However, they are only included when FIPS mode is disabled and are explicitly prefixed as 'InsecureKeyExchange...', indicating this is intentional for backward compatibility rather than a malicious pattern.

ssh/kex.go:622
low

PRNG seed predictability

NPS-2104A53906B4

portRandomizer uses math/rand seeded with time.Now().UnixNano() for the OpenSSH auto-port workaround. This is a weak randomness source, but it is only used to pick an arbitrary available port for a workaround, not for security-sensitive values like keys, tokens, or nonces. It is not a malicious pattern.

ssh/tcpip.go:60
low

Build-time Code Execution

NPS-AF571AEBCC6A

The file has a //go:build generate constraint and //go:generate directive, meaning it only runs during explicit code generation, not at import or normal build time. No init() functions or top-level code that executes on import. This is a standard Go code generation pattern.

x509roots/gen_fallback_bundle.go:7
low

Network Request

NPS-A54BBD2C7129

Fetches certdata.txt from a hardcoded Mozilla URL (https://hg.mozilla.org/mozilla-central/raw-file/tip/security/nss/lib/ckfw/builtins/certdata.txt). This is expected for a certificate bundle generator and the URL is configurable via flag. No data is exfiltrated; the request is a standard HTTPS GET with proper Content-Type validation.

x509roots/gen_fallback_bundle.go:57
low

File System Write

NPS-D636F1EF424E

Writes generated Go source and DER certificate bundle to paths specified by flags (defaults: fallback/bundle/bundle.go and fallback/bundle/bundle.der). This is the intended purpose of the generator and does not operate outside package scope without explicit user-provided paths.

x509roots/gen_fallback_bundle.go:145

Files reviewed

FileVerdictWhat the reviewer saw
openpgp/read.go critical The openpgp package is deprecated and unsafe by design, with multiple security weaknesses that can lead to message forgery, integrity bypass, and denial-of-service, making it critical for any application to avoid.
acme/internal/acmeprobe/prober.go medium The acme/internal/acmeprobe/prober.go file implements a legitimate ACME CA test prober; the only notable risks are an intentional but powerful exec-based DNS hook and a user-specified server bind address, neither of which indicates malicious intent.
openpgp/elgamal/elgamal.go medium The file is the legitimate Go standard-library ElGamal package with no malicious intent, but it ships deprecated, explicitly side-channel-vulnerable cryptography that constitutes a security warning for consumers.
openpgp/packet/packet.go medium The code implements OpenPGP packet parsing and is explicitly deprecated with known security issues, uses weak cryptographic algorithms, and has minor error handling and resource allocation concerns, but no active malicious patterns were detected.
openpgp/packet/public_key_v3.go medium Legitimate Go standard library OpenPGP v3 key handling code with expected legacy weak crypto (MD5 fingerprints, deprecated V3 keys) but no malicious patterns such as exfiltration, backdoors, or code execution.
openpgp/packet/signature.go medium The code appears to be a legitimate implementation of OpenPGP signature parsing and signing, but contains several robustness and input validation issues that could lead to denial-of-service or incorrect parsing, though no malicious patterns were detected.
openpgp/s2k/s2k.go medium The code contains no malicious patterns, but uses deprecated cryptographic primitives with weak defaults and is explicitly unmaintained, posing a security risk if used in production.
otr/otr.go medium No malicious patterns (exfiltration, backdoors, install hooks, shell execution, obfuscation) were detected; the code is a standard Go OTR implementation with deprecated cryptographic primitives (DSA-1024/SHA-1) inherent to the OTRv2 protocol.
ssh/agent/forward.go medium The code implements legitimate SSH agent forwarding functionality but includes patterns that could be risky if misused, such as connecting to arbitrary Unix sockets and unlimited goroutine spawning.
acme/acme.go safe This is a legitimate Go ACME client library from the Go standard library's x/crypto/acme package with no malicious patterns detected.
acme/autocert/autocert.go safe No malicious patterns detected; this is the standard Go autocert package implementing ACME certificate management with expected cryptographic and network operations.
acme/autocert/cache.go safe This is the standard Go autocert DirCache implementation with well-understood filesystem operations, path sanitization via filepath.Clean, and no malicious patterns such as exfiltration, process execution, or credential harvesting.
acme/autocert/internal/acmetest/ca.go safe This is a legitimate ACME test server used exclusively for Go package testing, with no malicious patterns, data exfiltration, or suspicious behavior detected.
acme/autocert/listener.go safe No malicious patterns detected
acme/autocert/renewal.go safe No malicious patterns detected; the code is a standard certificate renewal implementation from Go's acme/autocert package with no exfiltration, credential harvesting, obfuscation, or backdoor behavior.
acme/http.go safe The code is a legitimate Go ACME client HTTP implementation with standard retry logic, nonce handling, and request signing; no malicious patterns detected.
acme/jws.go safe No malicious patterns detected; the code is a legitimate ACME JWS implementation with standard cryptographic operations and no obfuscation, exfiltration, or dynamic execution.
acme/rfc8555.go safe This is a standard, legitimate Go implementation of the ACME protocol (RFC 8555) from the golang.org/x/crypto/acme package with no malicious patterns detected.
acme/types.go safe Cleared by Jev triage; no further analysis needed
argon2/argon2.go safe Cleared by Jev triage; no further analysis needed
argon2/blake2b.go safe Cleared by Jev triage; no further analysis needed
argon2/blamka_amd64.go safe No malicious patterns detected; this is a legitimate Go assembly helper file for Argon2's Blamka permutation with CPU feature detection and no network, filesystem, or execution abuse.
argon2/blamka_generic.go safe Cleared by Jev triage; no further analysis needed
argon2/blamka_ref.go safe Cleared by Jev triage; no further analysis needed
bcrypt/base64.go safe Cleared by Jev triage; no further analysis needed
Show 146 more files
FileVerdictWhat the reviewer saw
bcrypt/bcrypt.go safe Cleared by Jev triage; no further analysis needed
blake2b/blake2b.go safe Cleared by Jev triage; no further analysis needed
blake2b/blake2bAVX2_amd64.go safe No malicious patterns detected
blake2b/blake2b_generic.go safe Cleared by Jev triage; no further analysis needed
blake2b/blake2b_ref.go safe Cleared by Jev triage; no further analysis needed
blake2b/blake2x.go safe Cleared by Jev triage; no further analysis needed
blake2b/register.go safe No malicious patterns detected; the code only registers standard BLAKE2b hash implementations with Go's crypto package at init time.
blake2s/blake2s.go safe No malicious patterns detected
blake2s/blake2s_386.go safe Cleared by Jev triage; no further analysis needed
blake2s/blake2s_amd64.go safe Cleared by Jev triage; no further analysis needed
blake2s/blake2s_generic.go safe Cleared by Jev triage; no further analysis needed
blake2s/blake2s_ref.go safe Cleared by Jev triage; no further analysis needed
blake2s/blake2x.go safe Cleared by Jev triage; no further analysis needed
blowfish/block.go safe Cleared by Jev triage; no further analysis needed
blowfish/cipher.go safe Cleared by Jev triage; no further analysis needed
blowfish/const.go safe Cleared by Jev triage; no further analysis needed
bn256/bn256.go safe No malicious patterns detected; the code is a deprecated but legitimate Go cryptographic library implementation.
bn256/constants.go safe Cleared by Jev triage; no further analysis needed
bn256/curve.go safe Cleared by Jev triage; no further analysis needed
bn256/gfp12.go safe Cleared by Jev triage; no further analysis needed
bn256/gfp2.go safe Cleared by Jev triage; no further analysis needed
bn256/gfp6.go safe Cleared by Jev triage; no further analysis needed
bn256/optate.go safe Cleared by Jev triage; no further analysis needed
bn256/twist.go safe Cleared by Jev triage; no further analysis needed
cast5/cast5.go safe Cleared by Jev triage; no further analysis needed
chacha20/chacha_arm64.go safe Cleared by Jev triage; no further analysis needed
chacha20/chacha_generic.go safe Cleared by Jev triage; no further analysis needed
chacha20/chacha_noasm.go safe Cleared by Jev triage; no further analysis needed
chacha20/chacha_ppc64x.go safe Cleared by Jev triage; no further analysis needed
chacha20/chacha_s390x.go safe Cleared by Jev triage; no further analysis needed
chacha20/xor.go safe Cleared by Jev triage; no further analysis needed
chacha20poly1305/chacha20poly1305.go safe Cleared by Jev triage; no further analysis needed
chacha20poly1305/chacha20poly1305_amd64.go safe Cleared by Jev triage; no further analysis needed
chacha20poly1305/chacha20poly1305_generic.go safe Cleared by Jev triage; no further analysis needed
chacha20poly1305/chacha20poly1305_noasm.go safe Cleared by Jev triage; no further analysis needed
chacha20poly1305/fips140only_compat.go safe Cleared by Jev triage; no further analysis needed
chacha20poly1305/fips140only_go1.26.go safe Cleared by Jev triage; no further analysis needed
chacha20poly1305/xchacha20poly1305.go safe Cleared by Jev triage; no further analysis needed
cryptobyte/asn1.go safe No malicious patterns detected
cryptobyte/asn1/asn1.go safe Cleared by Jev triage; no further analysis needed
cryptobyte/builder.go safe Cleared by Jev triage; no further analysis needed
cryptobyte/string.go safe Cleared by Jev triage; no further analysis needed
curve25519/curve25519.go safe No malicious patterns detected; the code is a standard, frozen Go wrapper for X25519 using crypto/ecdh with no network, filesystem, process, or obfuscation concerns.
ed25519/ed25519.go safe This is a standard, frozen Go wrapper around crypto/ed25519 with no malicious patterns; it contains only type aliases and thin delegating functions to the standard library.
hkdf/hkdf.go safe No malicious patterns detected; the code is a standard, legitimate implementation of HKDF from the Go standard library ecosystem.
internal/alias/alias.go safe No malicious patterns detected; the code is a standard memory aliasing utility using unsafe pointers for overlap checks without any exfiltration, execution, or persistence behavior.
internal/alias/alias_purego.go safe Cleared by Jev triage; no further analysis needed
internal/poly1305/mac_noasm.go safe Cleared by Jev triage; no further analysis needed
internal/poly1305/poly1305.go safe Cleared by Jev triage; no further analysis needed
internal/poly1305/sum_asm.go safe Cleared by Jev triage; no further analysis needed
internal/poly1305/sum_generic.go safe No malicious patterns detected; code is a legitimate Go Poly1305 cryptographic implementation with only standard library usage.
internal/poly1305/sum_s390x.go safe Cleared by Jev triage; no further analysis needed
internal/testenv/exec.go safe The code is a legitimate test helper for managing subprocesses with timeouts and cleanup; it contains no malicious patterns despite using process spawning and environment variable reads.
internal/testenv/testenv_notunix.go safe Cleared by Jev triage; no further analysis needed
internal/testenv/testenv_unix.go safe No malicious patterns detected
md4/md4.go safe The code implements the standard MD4 hash algorithm as found in Go's crypto packages, with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, or network activity.
md4/md4block.go safe Cleared by Jev triage; no further analysis needed
nacl/auth/auth.go safe Cleared by Jev triage; no further analysis needed
nacl/box/box.go safe This is the standard Go x/crypto/nacl/box implementation providing public-key authenticated encryption with no malicious patterns detected.
nacl/secretbox/secretbox.go safe Cleared by Jev triage; no further analysis needed
nacl/sign/sign.go safe No malicious patterns detected; the code is a straightforward wrapper around crypto/ed25519 from the Go standard library with no network, filesystem, process, or dynamic code execution activity.
ocsp/ocsp.go safe No malicious patterns detected; the code is the standard Go OCSP package with only cryptographic parsing and signing operations.
openpgp/armor/armor.go safe No malicious patterns detected; the code is a legitimate, standard library implementation of OpenPGP ASCII Armor decoding with no exfiltration, credential harvesting, or other suspicious behavior.
openpgp/armor/encode.go safe Cleared by Jev triage; no further analysis needed
openpgp/canonical_text.go safe Cleared by Jev triage; no further analysis needed
openpgp/clearsign/clearsign.go safe This is the standard Go clearsign package source, marked deprecated for known design weaknesses but containing no malicious patterns such as exfiltration, credential harvesting, obfuscation, process spawning, or network backdoors.
openpgp/errors/errors.go safe Cleared by Jev triage; no further analysis needed
openpgp/keys.go safe No malicious patterns detected
openpgp/packet/compressed.go safe No malicious patterns detected in this standard OpenPGP compressed packet implementation; it performs only in-memory compression/decompression using Go standard libraries without network, filesystem, process, or dynamic code execution.
openpgp/packet/config.go safe Cleared by Jev triage; no further analysis needed
openpgp/packet/encrypted_key.go safe No malicious patterns detected; the code is a standard OpenPGP encrypted key packet implementation from the Go standard library with no data exfiltration, credential harvesting, obfuscation, or backdoor behavior.
openpgp/packet/literal.go safe No malicious patterns detected
openpgp/packet/ocfb.go safe Cleared by Jev triage; no further analysis needed
openpgp/packet/one_pass_signature.go safe Cleared by Jev triage; no further analysis needed
openpgp/packet/opaque.go safe No malicious patterns detected; this is a legitimate OpenPGP opaque packet parsing implementation from the official Go crypto library with no network, filesystem, process execution, or obfuscation behaviors.
openpgp/packet/private_key.go safe No malicious patterns detected in the OpenPGP private key parsing code; it implements standard cryptographic key handling per RFC 4880 without exfiltration, backdoors, or suspicious behavior.
openpgp/packet/public_key.go safe This is a standard OpenPGP public key parsing module from the Go x/crypto library; no malicious patterns such as data exfiltration, credential harvesting, obfuscation, network activity, or code execution were found.
openpgp/packet/reader.go safe No malicious patterns detected; the code is a standard OpenPGP packet reader with a recursion limit to prevent CVE-2013-4402.
openpgp/packet/signature_v3.go safe No malicious patterns detected; the code is a standard OpenPGP v3 signature parser/serializer with no exfiltration, credential harvesting, obfuscation, or command execution.
openpgp/packet/symmetric_key_encrypted.go safe No malicious patterns detected; the code is a standard OpenPGP symmetric key encryption packet implementation from golang.org/x/crypto/openpgp.
openpgp/packet/symmetrically_encrypted.go safe This is a legitimate Go standard library implementation of OpenPGP symmetrically encrypted packets with MDC integrity checking; no malicious patterns detected.
openpgp/packet/userattribute.go safe Cleared by Jev triage; no further analysis needed
openpgp/packet/userid.go safe Cleared by Jev triage; no further analysis needed
openpgp/write.go safe No malicious patterns detected; the code is a legitimate Go OpenPGP implementation from the official golang.org/x/crypto library.
otr/smp.go safe No malicious patterns detected; the code implements the OTR Socialist Millionaires Protocol using standard cryptographic primitives without any exfiltration, backdoor, or suspicious behavior.
pbkdf2/pbkdf2.go safe Cleared by Jev triage; no further analysis needed
pkcs12/bmp-string.go safe Cleared by Jev triage; no further analysis needed
pkcs12/crypto.go safe Cleared by Jev triage; no further analysis needed
pkcs12/errors.go safe Cleared by Jev triage; no further analysis needed
pkcs12/internal/rc2/rc2.go safe Cleared by Jev triage; no further analysis needed
pkcs12/mac.go safe This is standard PKCS#12 MAC verification code with a sensible iteration limit and no malicious patterns detected.
pkcs12/pbkdf.go safe Cleared by Jev triage; no further analysis needed
pkcs12/pkcs12.go safe No malicious patterns detected; the file is a standard Go implementation of PKCS#12 decoding from the standard library with no exfiltration, code execution, network, or filesystem abuse.
pkcs12/safebags.go safe No malicious patterns detected
poly1305/poly1305_compat.go safe This is a legitimate, deprecated compatibility wrapper around Go's standard golang.org/x/crypto/internal/poly1305 package with no malicious patterns.
ripemd160/ripemd160.go safe No malicious patterns detected; the file is a standard, unmodified implementation of the deprecated RIPEMD-160 hash algorithm.
ripemd160/ripemd160block.go safe Cleared by Jev triage; no further analysis needed
salsa20/salsa/hsalsa20.go safe Cleared by Jev triage; no further analysis needed
salsa20/salsa/salsa208.go safe Cleared by Jev triage; no further analysis needed
salsa20/salsa/salsa20_amd64.go safe Cleared by Jev triage; no further analysis needed
salsa20/salsa/salsa20_noasm.go safe Cleared by Jev triage; no further analysis needed
salsa20/salsa/salsa20_ref.go safe Cleared by Jev triage; no further analysis needed
salsa20/salsa20.go safe Cleared by Jev triage; no further analysis needed
scrypt/scrypt.go safe Cleared by Jev triage; no further analysis needed
sha3/hashes.go safe Cleared by Jev triage; no further analysis needed
sha3/legacy_hash.go safe No malicious patterns detected; the file is a legitimate Keccak hash implementation with standard cryptographic code and no exfiltration, persistence, or obfuscation.
sha3/legacy_keccakf.go safe Cleared by Jev triage; no further analysis needed
sha3/shake.go safe Cleared by Jev triage; no further analysis needed
ssh/agent/client.go safe No malicious patterns detected; this is the standard Go ssh-agent client implementation with legitimate protocol handling and no exfiltration, code execution, or credential harvesting behavior.
ssh/agent/keyring.go safe No malicious patterns detected in the SSH agent keyring implementation.
ssh/agent/server.go safe No malicious patterns detected; this is the standard Go SSH agent server implementation with appropriate input validation and resource limits.
ssh/buffer.go safe Cleared by Jev triage; no further analysis needed
ssh/certs.go safe This is a legitimate Go crypto/SSH certificate handling file from the golang.org/x/crypto/ssh package with no malicious patterns detected.
ssh/channel.go safe This is the standard Go x/crypto/ssh channel implementation with normal flow-control, packet handling, and request management; no malicious patterns, exfiltration, credential harvesting, dynamic execution, or install-time behavior were detected.
ssh/cipher.go safe This is the standard Go x/crypto/ssh cipher implementation with no malicious patterns; it contains only legitimate SSH encryption/decryption logic, including intentionally insecure ciphers (RC4, CBC, 3DES) that are clearly marked as insecure and excluded from default configuration.
ssh/client.go safe No malicious patterns detected; this is legitimate Go SSH client code from the official golang.org/x/crypto/ssh package with no exfiltration, credential harvesting, obfuscation, or dynamic code execution.
ssh/client_auth.go safe This is a legitimate, unmodified portion of the Go standard library's x/crypto/ssh package implementing SSH client authentication; no malicious patterns, exfiltration, credential harvesting, obfuscation, or unauthorized execution were detected.
ssh/common.go safe This is the standard Go x/crypto/ssh common.go file containing algorithm definitions and helpers with no malicious patterns detected.
ssh/connection.go safe No malicious patterns detected; this is standard Go SSH connection interface and metadata code from the golang.org/x/crypto/ssh package with no exfiltration, credential harvesting, obfuscation, process spawning, or suspicious network activity.
ssh/control.go safe No malicious patterns detected; the code implements a legitimate SSH ControlMaster proxy handshake and transport without any exfiltration, credential harvesting, obfuscation, or backdoor behavior.
ssh/doc.go safe Cleared by Jev triage; no further analysis needed
ssh/handshake.go safe No malicious patterns detected; the code is a legitimate SSH handshake implementation from the Go standard library's x/crypto/ssh package.
ssh/internal/bcrypt_pbkdf/bcrypt_pbkdf.go safe Cleared by Jev triage; no further analysis needed
ssh/kex.go safe This is a legitimate Go SSH key exchange implementation with no evidence of malicious activity; only standard legacy-cipher backward-compatibility concerns are present.
ssh/keys.go safe This is the standard golang.org/x/crypto/ssh keys implementation handling public/private key parsing, marshaling, signing, and verification with no malicious patterns such as exfiltration, credential harvesting, obfuscated execution, or process spawning.
ssh/knownhosts/knownhosts.go safe This is the legitimate golang.org/x/crypto/ssh/knownhosts package; no malicious patterns such as exfiltration, credential harvesting, obfuscation, shells, or install-time execution were found.
ssh/mac.go safe No malicious patterns detected
ssh/messages.go safe This is the standard Go crypto/ssh messages.go file implementing SSH wire format marshaling/unmarshaling with no malicious patterns, network exfiltration, credential harvesting, or code execution.
ssh/mlkem.go safe The file implements a standard hybrid post-quantum key exchange (ML-KEM768 with Curve25519) from the official Go SSH package, with no malicious patterns detected.
ssh/mux.go safe The file is a standard part of the Go SSH library (ssh/mux.go) containing only legitimate channel multiplexing logic with no malicious patterns such as data exfiltration, credential harvesting, obfuscation, shell commands, or network abuse.
ssh/server.go safe This is the standard Go x/crypto/ssh server implementation, and no malicious patterns such as exfiltration, credential harvesting, obfuscation, backdoors, or install-time execution were detected.
ssh/session.go safe No malicious patterns detected
ssh/ssh_gss.go safe The code is part of Go's SSH library implementing GSSAPI/Kerberos authentication interfaces and contains only standard, benign initialization and parsing logic with no malicious patterns.
ssh/streamlocal.go safe No malicious patterns detected
ssh/tcpip.go safe This is the standard Go x/crypto/ssh tcpip.go implementation for SSH port forwarding; no malicious patterns, exfiltration, backdoors, or process execution were detected.
ssh/terminal/terminal.go safe No malicious patterns detected; the file is a thin deprecated wrapper delegating to golang.org/x/term with no network, filesystem, process, or dynamic execution behavior.
ssh/testdata/doc.go safe Cleared by Jev triage; no further analysis needed
ssh/testdata/keys.go safe Cleared by Jev triage; no further analysis needed
ssh/transport.go safe This is a legitimate Go SSH transport implementation from the official Go crypto library with no malicious patterns detected.
tea/cipher.go safe Cleared by Jev triage; no further analysis needed
twofish/twofish.go safe Cleared by Jev triage; no further analysis needed
x509roots/gen_fallback_bundle.go safe This is a legitimate Go code generator for fallback certificate bundles that fetches and parses Mozilla NSS certdata; no malicious patterns detected.
x509roots/nss/parser.go safe No malicious patterns detected; the code is a legitimate NSS certdata.txt parser with no network, credential, or code-execution behavior.
xtea/block.go safe Cleared by Jev triage; no further analysis needed
xtea/cipher.go safe Cleared by Jev triage; no further analysis needed
xts/xts.go safe Cleared by Jev triage; no further analysis needed

Frequently asked questions

Is golang.org/x/crypto safe to use?

golang.org/x/crypto@v0.57.0 has 1 critical, 3 high, 18 medium, 28 low severity findings, including behavior that is dangerous or likely malicious. Do not install it without reviewing the findings.

Does golang.org/x/crypto contain malware?

The latest scan of golang.org/x/crypto (v0.57.0) flagged critical behavior consistent with malicious or dangerous code. See the findings on this page for the exact files and lines.

How was golang.org/x/crypto checked?

Togoder Security downloaded the published Go package and had an AI model read its 171 source files, looking for install scripts, credential access, network exfiltration, obfuscation, backdoors and crypto-wallet theft. The results are cached by file hash and shown here.

How do I scan golang.org/x/crypto together with the rest of my dependencies?

Upload your lockfile at https://security.togoder.click/scan or call the API documented at https://security.togoder.click/api-docs. Files that have already been scanned, like the ones in golang.org/x/crypto@v0.57.0, cost nothing.

Related security reports