# golang.org/x/net@v0.59.0 security report (Go)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-05T19:09:50.000Z
- Files reviewed: 513
- Findings: 11 medium, 42 low severity findings
- Report: https://security.togoder.click/go/golang.org/x/net
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the Go package golang.org/x/net@v0.59.0 on Oct 5, 2026. An AI review of 513 source files produced 11 medium, 42 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Deprecated package with known buffering concern

Finding ID: `NPS-A24800D977F5`

File: `http2/h2c/h2c.go`

The NewHandler documentation explicitly warns that the first request on an h2c connection is read entirely into memory before the Handler is called, which can lead to unbounded memory consumption if not wrapped in http.MaxBytesHandler. This is a documented design limitation rather than an intentional backdoor, but it can be abused for denial-of-service.

### [medium] Insecure TLS configuration

Finding ID: `NPS-8674AEB880B5`

File: `http2/h2i/h2i.go:191`

The -insecure flag sets InsecureSkipVerify: true in the tls.Config, disabling certificate validation. While this is intentional for a diagnostic tool, it allows man-in-the-middle attacks if used carelessly.

### [medium] Hostname verification bypass

Finding ID: `NPS-C6B5D430223A`

File: `http2/h2i/h2i.go:218`

When -insecure is set, VerifyHostname is explicitly skipped, further weakening TLS security and allowing connections to servers with mismatched certificates.

### [medium] Unsafe linkname directive

Finding ID: `NPS-3751525576EC`

File: `http3/http3.go:12`

The file uses `//go:linkname` to link to unexported functions in the `net/http_test` package (`registerHTTP3Server` and `registerHTTP3Transport`). This mechanism bypasses Go's type safety and package encapsulation, and is generally discouraged in production code. It can be used to access internal APIs not intended for public use. While the apparent purpose is to allow tests to pass options structs to registration functions, this pattern introduces fragility and potential for abuse if the target package changes or if the linkname is manipulated maliciously.

### [medium] Insecure TLS configuration

Finding ID: `NPS-B46D5F7211C3`

File: `internal/quic/cmd/interop/main.go:47`

TLSConfig sets InsecureSkipVerify: true, disabling certificate verification. This is expected for interoperability testing but would be dangerous in production and could facilitate MITM attacks if this code were reused or run outside the interop test context.

### [medium] File system access from environment-controlled paths

Finding ID: `NPS-44E37CDA3E5C`

File: `internal/quic/cmd/interop/main.go:189`

The -root, -output, and -qlog flags control where files are read from and written to. Although paths are validated with filepath.IsLocal on request paths, the root/output directories themselves are attacker-influenced and used for file operations, which could write arbitrary files to unintended locations if defaults are empty.

### [medium] unsafe pointer usage

Finding ID: `NPS-BFBD4F8F862B`

File: `internal/socket/socket.go:137`

The code uses unsafe.Pointer to cast byte slices directly into cmsghdr structs in MarshalHeader, ParseHeader, Marshal, and Parse methods. While this is standard practice in Go's low-level networking libraries and appears legitimate, incorrect bounds checking could lead to memory corruption or out-of-bounds reads. The parsing logic in Parse() does include numerous length validations, but direct memory reinterpretation via unsafe.Pointer is inherently risky.

### [medium] Remote Code Generation

Finding ID: `NPS-32A2EC148C45`

File: `ipv4/gen.go:110`

The parseICMPv4Parameters function processes XML from a remote source and emits Go source code derived from remote descriptions. If the remote server or MITM attacker supplied malicious XML, the generated code could contain unexpected constants, though format.Source would likely reject syntactically invalid code. This represents a potential supply chain risk.

### [medium] network_request

Finding ID: `NPS-242E0134F0A8`

File: `ipv6/gen.go:77`

The geniana function performs an unauthenticated HTTP GET request to a hardcoded external URL (https://www.iana.org/assignments/icmpv6-parameters/icmpv6-parameters.xml) and parses the response. While this is a legitimate IANA registry, fetching and processing remote XML without integrity verification (e.g., signature or hash check) at generation time could allow a compromised or spoofed response to inject malicious constants into generated code.

### [medium] authorization depends on unverified RemoteAddr

Finding ID: `NPS-ABB682E6F530`

File: `trace/trace.go:100`

AuthRequest decides access solely based on req.RemoteAddr (host portion). Behind a reverse proxy or when a client can influence RemoteAddr (e.g., X-Forwarded-For misconfiguration, unix sockets, or non-TCP transports), remote requests could appear to originate from localhost, bypassing the only access control. The package provides no additional token/secret check.

### [medium] debug/pprof-style information disclosure endpoint

Finding ID: `NPS-4AF8F433CF02`

File: `trace/trace.go:184`

The package registers HTTP handlers on the DefaultServeMux at /debug/requests and /debug/events and exposes internal trace data (titles, events, IDs, timing, call stacks) via an HTML page. Although AuthRequest defaults to allowing only localhost (letting an operator serve it on a private interface), the handler is bound globally and inherits any external-facing listener or reverse proxy using DefaultServeMux, which could expose sensitive diagnostic data (URL paths, error messages, IDs, stack traces) to remote clients if the default is customized or if RemoteAddr is spoofed in a proxy configuration.

### [low] debug utility

Finding ID: `NPS-0D43D96459CB`

File: `http2/gotrack.go`

This file is a defensive debug-only utility that tracks goroutine IDs for internal consistency checks. It reads an environment variable DEBUG_HTTP2_GOROUTINES to enable debugging and uses runtime.Stack to parse goroutine IDs. No network, file system, process spawning, or obfuscated code is present.

### [low] Use of GODEBUG environment variable

Finding ID: `NPS-DF0E587DF796`

File: `http2/h2c/h2c.go:48`

The init() function reads the GODEBUG environment variable to enable verbose HTTP/2 logging. This is a standard Go debugging mechanism, not credential harvesting, but it is an environment variable read at import time.

### [low] External network connections controlled by flags

Finding ID: `NPS-AC73B8BA475C`

File: `http2/h2i/h2i.go:200`

The tool dials arbitrary hosts/ports specified on the command line, including a -dial flag that permits connecting to a different SNI name. This is expected behavior for an interactive HTTP/2 client but could be abused if the binary is invoked with untrusted arguments.

### [low] Terminal raw mode manipulation

Finding ID: `NPS-3BC7585DBBA2`

File: `http2/h2i/h2i.go:235`

The program sets the terminal to raw mode via term.MakeRaw, capturing all keystrokes. This is standard for interactive consoles but could theoretically capture sensitive input if the user types credentials.

### [low] import time code execution

Finding ID: `NPS-3F97569ADAB0`

File: `http2/http2.go:40`

The init() function runs at import time, which is normal for Go packages. It only configures logging and protocol flags based on environment variables and does not perform any malicious actions.

### [low] environment variable usage

Finding ID: `NPS-C2B6FA2A7DA7`

File: `http2/http2.go:41`

The init() function reads the GODEBUG environment variable to enable verbose logging and extended CONNECT protocol. This is a standard Go debugging mechanism, not credential harvesting or exfiltration. It only checks for specific substrings (http2debug=1, http2debug=2, http2xconnect=1) and does not send data externally.

### [low] Resource management

Finding ID: `NPS-7019C1C94BE5`

File: `http2/write.go:96`

In writeGoAway.writeFrame, the error returned by ctx.Flush() is deliberately ignored. This is intentional and documented ('ignore error: we're hanging up on them anyway') and does not introduce a security vulnerability.

### [low] Panic on unexpected input

Finding ID: `NPS-BEC54F280BC9`

File: `http2/write.go:208`

writeResHeaders.writeFrame and writePushPromise.writeFrame panic if the HPACK header block is empty. The code comments suggest this should be unreachable, but a panic could be triggered by unusual header state, potentially causing a denial of service. This is likely an internal invariant rather than an attacker-controlled path.

### [low] Use of reflection for struct copying

Finding ID: `NPS-D74D7130D527`

File: `http3/http3.go:31`

The `shallowStructCopy` function uses reflection to copy fields from one struct to another. While this is a legitimate technique, it can be misused to bypass access controls or type checks. However, in this context, it enforces that all fields are exported and assignable, which mitigates some risks. Still, reflection-based manipulation can be a vector for unexpected behavior if the source or destination types are not fully trusted.

### [low] Potential panic on invalid input

Finding ID: `NPS-E2BA9CB90092`

File: `internal/http3/settings.go:23`

The writeSettings function notes that settings values that don't fit in a QUIC varint will panic when sizeVarint is called. This is a robustness issue but not malicious; it's a standard Go library implementation where callers are expected to provide valid values. It could lead to a denial of service if an attacker can control the settings values, but the function is internal and likely called with trusted constants.

### [low] network_fetch_in_generate

Finding ID: `NPS-9C2B526BE524`

File: `internal/iana/gen.go:44`

The program fetches XML registries over HTTPS from www.iana.org only during 'go generate' and writes generated Go constants locally. These are expected, bounded, and not malicious.

### [low] file_write

Finding ID: `NPS-193499EF3699`

File: `internal/iana/gen.go:65`

Writes generated output to 'const.go' in the current directory. This is intended generator behavior, not package runtime behavior, and is gated behind the 'ignore' build tag.

### [low] Environment variable harvesting

Finding ID: `NPS-54BAAE9C672E`

File: `internal/quic/cmd/interop/main.go:70`

Reads SSLKEYLOGFILE environment variable and writes TLS session keys to the specified file, which could leak sensitive secrets if the env var is set in an untrusted environment.

### [low] Unsanitized file path usage

Finding ID: `NPS-B5B84BD821E9`

File: `internal/quic/cmd/interop/main.go:197`

serveReq joins *root with the request path after only checking filepath.IsLocal. While IsLocal blocks traversal, it still permits opening arbitrary local files under root, which is the intended server behavior but is a file-system exposure surface.

### [low] unsafe pointer usage

Finding ID: `NPS-4119D285D30D`

File: `internal/socket/iovec_32bit.go:17`

The set method uses unsafe.Pointer to obtain a pointer to the first byte of the slice. This is a standard pattern in Go networking libraries (e.g., golang.org/x/net) for constructing iovec structures for syscalls like readv/writev. The pointer is set to &b[0], which is safe because the length check ensures the slice is non-empty. No memory is accessed beyond the slice bounds.

### [low] unsafe pointer usage

Finding ID: `NPS-7C00CC236164`

File: `internal/socket/iovec_64bit.go:16`

This file uses the unsafe package to convert a byte slice into a raw pointer for an I/O vector (iovec). While the pointer is only stored and length is bounded by the slice length, any future misuse could lead to memory safety issues. The code is legitimate and standard for the golang.org/x/sys/unix package.

### [low] low-level socket control message manipulation

Finding ID: `NPS-79D9DEBBA493`

File: `internal/socket/socket.go:88`

The ControlMessage type provides direct kernel-level sendmsg/recvmsg control message marshaling and parsing. Malformed control messages can be used in exploits (e.g., CMSG parsing bugs), though this appears to be legitimate golang.org/x/net code that mirrors upstream Go source.

### [low] system call interface

Finding ID: `NPS-600308445C31`

File: `internal/socket/socket.go:253`

Methods RecvMsg, SendMsg, RecvMsgs, SendMsgs expose raw recvmsg/sendmsg/recvmmsg/sendmmsg syscalls to callers with caller-controlled flags. This is expected functionality for a socket utility package, but provides a powerful interface that could be misused by dependents.

### [low] No evidence of malicious behavior

Finding ID: `NPS-D7103D02D327`

File: `internal/socket/sys_unix.go`

The code performs standard socket option and message operations (getsockopt, setsockopt, recvmsg, sendmsg) and address conversions. There is no data exfiltration, credential harvesting, obfuscation, dynamic code execution, cryptocurrency mining, backdoor, network calls to external servers, file system manipulation, process spawning, or dynamic imports. The code is consistent with the legitimate golang.org/x/net package.

### [low] Use of unsafe package and linkname directives

Finding ID: `NPS-1B9DE7598C9D`

File: `internal/socket/sys_unix.go:15`

The file uses //go:linkname to access unexported syscall functions (syscall.getsockopt, syscall.setsockopt) and unsafe.Pointer operations. While this is a known pattern in the golang.org/x/net/internal/socket package for performance and compatibility reasons, it bypasses Go's type safety and relies on internal runtime details that may change. However, no malicious payload is present.

### [low] Potential unsafe pointer usage on empty slice

Finding ID: `NPS-16610EA1A2D5`

File: `internal/socket/sys_unix.go:25`

Both getsockopt and setsockopt pass unsafe.Pointer(&b[0]) without checking that len(b) > 0. If an empty slice is passed, this would cause an index out of range panic. This is a correctness/robustness issue rather than a security vulnerability, but it's an unsafe pattern.

### [low] Process Execution

Finding ID: `NPS-EA847DA48E3B`

File: `ipv4/gen.go:52`

The code executes the external command 'go tool cgo -godefs' via os/exec. This is a standard part of the Go toolchain and is gated behind the 'ignore' build tag, so it only runs during explicit code generation, not during normal package import/build. However, spawning subprocesses is a pattern that warrants scrutiny in a malicious context.

### [low] File System Writes

Finding ID: `NPS-AA77ABEDFF76`

File: `ipv4/gen.go:66`

The code writes generated Go source files (zsys_*.go and iana.go) to the current directory. This is expected behavior for a code generator, but writing files based on network content could allow an attacker controlling the remote registry to inject arbitrary code into generated files.

### [low] Network Requests

Finding ID: `NPS-5343C17CF877`

File: `ipv4/gen.go:78`

The code fetches XML data from an external IANA URL (https://www.iana.org/assignments/icmp-parameters/icmp-parameters.xml) via http.Get. While this is a legitimate source for protocol constants, it demonstrates external network dependency and could be a vector for supply chain issues if the remote content were compromised or if the URL were altered in a malicious fork.

### [low] Unsafe pointer usage

Finding ID: `NPS-DE4571B96BD5`

File: `ipv4/sockopt_posix.go:39`

Uses unsafe.Pointer for type conversion in getICMPFilter and setICMPFilter. This is a common and legitimate pattern in low-level networking code for zero-copy struct conversion, but could theoretically lead to memory safety issues if sizes mismatched.

### [low] cgo type definitions

Finding ID: `NPS-639865DA1D84`

File: `ipv6/defs_freebsd.go`

This file uses cgo to map C struct types from system headers (sys/socket.h, netinet/in.h, netinet/icmp6.h) to Go types for IPv6 socket programming. It is a standard Go x/net style generated definition file guarded by //go:build ignore, meaning it is not compiled as part of the normal build. It contains no executable logic, network calls, file I/O, process spawning, or dynamic code execution.

### [low] spawning_process

Finding ID: `NPS-12D4212CEA5F`

File: `ipv6/gen.go:45`

genzsys executes an external command via exec.Command("go", "tool", "cgo", "-godefs", defs). The 'go' binary is resolved via PATH, which in a hostile environment could be hijacked; however, this is standard for Go code generation and argument injection is limited to runtime.GOOS-derived filenames.

### [low] file_system_write

Finding ID: `NPS-2ED369380458`

File: `ipv6/gen.go:57`

The program writes generated files (zsys_*.go, iana.go) to the current working directory using os.WriteFile with fixed names derived from runtime.GOOS/GOARCH and hardcoded strings. Writes are confined to expected generated-file names, so risk is limited.

### [low] Unsafe pointer arithmetic

Finding ID: `NPS-FF50FC765590`

File: `ipv6/sys_darwin.go:61`

The code uses unsafe.Pointer with fixed offsets to access fields in groupReq and groupSourceReq structs. While this is standard practice in Go's syscall/net packages to match OS-level struct layouts, it is a fragile pattern that could lead to memory corruption if offsets are incorrect. However, no malicious intent is present.

### [low] platform-specific code

Finding ID: `NPS-80C4106A0D8B`

File: `ipv6/sys_ssmreq.go:24`

Code contains architecture-specific handling for FreeBSD 32-bit compatibility, which is legitimate for socket options. No suspicious behavior detected.

### [low] unsafe usage

Finding ID: `NPS-175DCABF51EA`

File: `ipv6/sys_ssmreq.go:30`

Use of unsafe.Pointer for struct-to-byte conversion is standard in this Go networking library but could theoretically lead to memory safety issues if struct sizes or layouts change. However, this is not malicious and is guarded by build constraints and platform-specific code.

### [low] File System Operation

Finding ID: `NPS-E3DC90B247A5`

File: `nettest/nettest.go`

LocalPath() creates a temporary file via os.CreateTemp and then removes it to obtain a unique path for Unix domain socket tests. No tampering with files outside the temporary directory occurs.

### [low] Process Execution

Finding ID: `NPS-B7505D489518`

File: `nettest/nettest.go:51`

The code executes the external command 'oslevel' on AIX systems to check the OS version for Unix socket support. This is a benign, read-only system query with no user input involved.

### [low] Environment variable access

Finding ID: `NPS-F698F9903B10`

File: `quic/log.go:15`

The init() function reads the GODEBUG environment variable to enable packet logging. This is a standard Go debugging mechanism and does not harvest credentials or exfiltrate data. Logging is opt-in and writes only to stdout, not to external servers or files.

### [low] init function execution

Finding ID: `NPS-2646D9705E11`

File: `route/sys.go:23`

The init() function runs at import time as part of Go's standard initialization semantics. It only performs endianness detection and calls probeRoutingStack() to configure local routing table parsing parameters. No external commands, network activity, or file access occur.

### [low] unsafe pointer usage

Finding ID: `NPS-C7F2D882A5FB`

File: `route/sys.go:26`

unsafe.Pointer is used only to determine native endianness by inspecting the first byte of a uint32. This is a common, benign idiom in the Go standard library and does not permit arbitrary memory access here.

### [low] syscall usage

Finding ID: `NPS-7E32C0AA7E61`

File: `route/sys.go:32`

syscall.RTM_VERSION is referenced as a constant fallback for the routing message version. No privileged syscall operations or side effects are performed in this file.

### [low] import-time side effect / global HTTP registration

Finding ID: `NPS-E414530CE7D4`

File: `trace/trace.go:174`

An init() function registers fixed handlers on http.DefaultServeMux and panics if /debug/requests is already registered. This executes at import time and takes over global routing, which is an unexpected invasive side effect for a library and can affect any program that imports the package (directly or transitively).

### [low] panic causing denial of service

Finding ID: `NPS-FBCE204E5856`

File: `trace/trace.go:176`

The init() function panics when /debug/requests is already registered on DefaultServeMux. Merely importing two copies of golang.org/x/net/trace (e.g., through vendoring) will crash the process at startup, creating a trivially reachable DoS if dependency resolution produces duplicates.

### [low] sensitive data rendered without sufficient redaction defaults

Finding ID: `NPS-07E4815B0012`

File: `trace/trace.go:238`

Trace titles/events include request URL paths and error messages. Sensitive flag defaults to false for many entries (e.g., LazyPrintf always uses sensitive=false), so unless ShowSensitive is explicitly turned off (only via the optional 'show_sensitive=0' query parameter), potentially sensitive request details are rendered to anyone who can reach the debug endpoints.

### [low] ChartsReader custom reader

Finding ID: `NPS-8D79609ECB44`

File: `webdav/internal/xml/xml.go:154`

The Decoder.CharsetReader field allows the caller to supply a function which returns an io.Reader that is used by the parser. This is not suspicious by itself as it is a documented feature of the stdlib encoding/xml package. No malicious use is present in this file.

### [low] no malicious patterns

Finding ID: `NPS-C5A020701DBD`

File: `websocket/websocket.go`

The file is a standard implementation of the WebSocket protocol from the Go standard library (golang.org/x/net/websocket). It contains no data exfiltration, credential harvesting, obfuscated code, dynamic code execution, crypto mining, backdoor/reverse shell, install-time execution, suspicious network requests, file system manipulation, process spawning, or dynamic imports with computed input. All imports and API usage are consistent with the stated purpose of implementing RFC 6455.

## Files reviewed

- `http2/h2c/h2c.go` (medium): The code is a deprecated, unmaintained Go standard-library-adjacent h2c implementation with a documented memory buffering risk and GODEBUG-based logging, but contains no malicious exfiltration, backdoor, or credential-harvesting patterns.
- `http2/h2i/h2i.go` (medium): This is the official Go x/net h2i diagnostic tool; no malicious patterns such as exfiltration, credential harvesting, or backdoors were found, but it intentionally disables TLS verification when the -insecure flag is used.
- `http3/http3.go` (medium): The code uses unsafe linkname and reflection for internal test integration, which are not inherently malicious but introduce security and stability risks.
- `internal/quic/cmd/interop/main.go` (medium): This is an official Go QUIC interop test client/server with intentional insecure test settings (InsecureSkipVerify, key logging) and file serving, but no overt malicious exfiltration, backdoor, or code-execution patterns.
- `internal/socket/iovec_64bit.go` (medium): The code is a standard part of Go's socket library and contains no malicious patterns, though it uses unsafe pointers as intended for low-level I/O operations.
- `internal/socket/socket.go` (medium): Legitimate Go x/net socket utility code with standard low-level unsafe pointer and syscall usage; no malicious patterns such as exfiltration, credentials theft, obfuscation, or backdoors detected, though unsafe pointer usage warrants caution.
- `internal/socket/sys_unix.go` (medium): The code appears to be a legitimate part of the golang.org/x/net internal socket package, using unsafe and linkname for low-level socket operations; no malicious patterns were found, though the unsafe practices warrant a low-severity warning.
- `ipv4/gen.go` (medium): This is a legitimate Go code generator (go:generate) for the golang.org/x/net/ipv4 package, but it makes external network requests and writes generated files, which introduces low-to-medium supply chain risks; it is not overtly malicious.
- `ipv6/gen.go` (medium): This is a legitimate Go code generator (guarded by //go:build ignore and only run manually via go generate) that fetches IANA ICMPv6 parameters over HTTP and invokes go tool cgo, with the main residual concern being lack of integrity verification on the remote XML source.
- `trace/trace.go` (medium): The code is the legitimate golang.org/x/net/trace package, but it registers globally-accessible debug HTTP endpoints at import time and relies on a spoofable RemoteAddr for authorization, which can lead to information disclosure of trace data exposed through DefaultServeMux.
- `bpf/asm.go` (safe): Cleared by Jev triage; no further analysis needed
- `bpf/constants.go` (safe): Cleared by Jev triage; no further analysis needed
- `bpf/doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `bpf/instructions.go` (safe): Cleared by Jev triage; no further analysis needed
- `bpf/setter.go` (safe): Cleared by Jev triage; no further analysis needed
- `bpf/vm.go` (safe): No malicious patterns detected
- `bpf/vm_instructions.go` (safe): No malicious patterns detected; the code is a standard BPF virtual machine instruction implementation from the Go standard library with only in-memory arithmetic, bounds-checked loads, and no network, file system, process, or dynamic code execution behavior.
- `context/context.go` (safe): Cleared by Jev triage; no further analysis needed
- `context/ctxhttp/ctxhttp.go` (safe): No malicious patterns detected
- `dict/dict.go` (safe): No malicious patterns detected; this is the standard Go dictionary protocol client library implementing RFC 2229 with no exfiltration, process spawning, or obfuscation.
- `dns/dnsmessage/message.go` (safe): Cleared by Jev triage; no further analysis needed
- `dns/dnsmessage/svcb.go` (safe): Cleared by Jev triage; no further analysis needed
- `html/atom/atom.go` (safe): Cleared by Jev triage; no further analysis needed
- `html/atom/gen.go` (safe): This is a standard Go code generator from the Go standard library that produces HTML atom lookup tables; it contains no malicious patterns, network calls, credential access, or dynamic code execution.
- `html/atom/table.go` (safe): No malicious patterns detected; this is a generated Go source file containing only static HTML atom definitions and lookup tables.
- `html/charset/charset.go` (safe): Cleared by Jev triage; no further analysis needed
- `html/const.go` (safe): Cleared by Jev triage; no further analysis needed
- `html/doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `html/doctype.go` (safe): Cleared by Jev triage; no further analysis needed
- `html/escape.go` (safe): Cleared by Jev triage; no further analysis needed
- `html/foreign.go` (safe): Cleared by Jev triage; no further analysis needed
- `html/iter.go` (safe): Cleared by Jev triage; no further analysis needed
- `html/node.go` (safe): Cleared by Jev triage; no further analysis needed
- `html/nodetype_string.go` (safe): Auto-generated stringer code for NodeType enum contains only standard String() method and compile-time assertions, with no malicious patterns.
- `html/parse.go` (safe): No malicious patterns detected; this is the standard Go html package parser with no network, filesystem, or code execution behavior.
- `html/render.go` (safe): Cleared by Jev triage; no further analysis needed
- `html/token.go` (safe): No malicious patterns detected; this is a legitimate Go standard library HTML tokenizer with no network, filesystem, process, or obfuscation concerns.
- `http/httpguts/guts.go` (safe): Cleared by Jev triage; no further analysis needed
- `http/httpguts/httplex.go` (safe): Cleared by Jev triage; no further analysis needed
- `http/httpproxy/proxy.go` (safe): No malicious patterns detected; the code is the standard Go httpproxy package for proxy configuration from environment variables.
- `http2/ascii.go` (safe): Cleared by Jev triage; no further analysis needed
- `http2/ciphers.go` (safe): Cleared by Jev triage; no further analysis needed
- `http2/client_conn_pool.go` (safe): No malicious patterns detected; this is the standard Go HTTP/2 client connection pool implementation with no exfiltration, credential harvesting, obfuscation, or unsafe execution behavior.
- `http2/client_priority_go126.go` (safe): Cleared by Jev triage; no further analysis needed
- `http2/client_priority_go127.go` (safe): Cleared by Jev triage; no further analysis needed
- `http2/clientconn.go` (safe): No malicious patterns detected; the file contains only standard, thin wrapper methods for an HTTP/2 client connection with no network exfiltration, credential harvesting, dynamic code execution, or other suspicious behavior.
- `http2/config.go` (safe): Cleared by Jev triage; no further analysis needed
- `http2/config_go125.go` (safe): Cleared by Jev triage; no further analysis needed
- `http2/config_go126.go` (safe): Cleared by Jev triage; no further analysis needed
- `http2/databuffer.go` (safe): Cleared by Jev triage; no further analysis needed
- `http2/errors.go` (safe): Cleared by Jev triage; no further analysis needed
- `http2/flow.go` (safe): Cleared by Jev triage; no further analysis needed
- `http2/frame.go` (safe): No malicious patterns detected; this is standard Go HTTP/2 frame parsing code from the golang.org/x/net package with no data exfiltration, credential harvesting, obfuscation, or backdoor behavior.
- `http2/gotrack.go` (safe): No malicious patterns detected; the code is a benign debug utility from the Go standard library's http2 package.
- `http2/hpack/encode.go` (safe): Cleared by Jev triage; no further analysis needed
- `http2/hpack/gen.go` (safe): This is a legitimate Go code generation tool from the official golang.org/x/net/http2/hpack package that generates static HPACK table definitions; it contains no malicious patterns, network access, credential harvesting, or dynamic code execution.
- `http2/hpack/hpack.go` (safe): This is a standard implementation of HPACK header compression for HTTP/2 from the Go standard library, with no malicious patterns or security concerns detected.
- `http2/hpack/huffman.go` (safe): Cleared by Jev triage; no further analysis needed
- `http2/hpack/static_table.go` (safe): No malicious patterns detected; this is a standard HPACK static table definition for HTTP/2 header compression.
- `http2/hpack/tables.go` (safe): Cleared by Jev triage; no further analysis needed
- `http2/http2.go` (safe): The code is a legitimate part of the Go standard library's HTTP/2 implementation (golang.org/x/net/http2) with no malicious patterns; the only environment variable access is standard Go debugging configuration.
- `http2/pipe.go` (safe): Cleared by Jev triage; no further analysis needed
- `http2/server.go` (safe): No malicious patterns detected; this is a legitimate copy of the standard Go HTTP/2 server implementation from golang.org/x/net/http2.
- `http2/server_common.go` (safe): Cleared by Jev triage; no further analysis needed
- `http2/server_wrap.go` (safe): No malicious patterns detected in the reviewed Go source file; it contains standard HTTP/2 server configuration and compatibility code with no exfiltration, credential harvesting, obfuscation, or process execution.
- `http2/transport.go` (safe): This is the standard Go x/net/http2 Transport implementation with no malicious patterns, exfiltration, credential harvesting, or dynamic code execution detected.
- `http2/transport_common.go` (safe): No malicious patterns detected; this is standard Go HTTP/2 transport code from golang.org/x/net/http2 with no exfiltration, credential harvesting, obfuscation, or backdoor behavior.
- `http2/transport_wrap.go` (safe): No malicious patterns detected; the code is a legitimate part of Go's x/net/http2 transport wrapping implementation with no suspicious network, filesystem, process, or obfuscation behavior.
- `http2/unencrypted.go` (safe): No malicious patterns detected; the code is a utility for retrieving an unencrypted net.Conn from a *tls.Conn with strict type checking.
- `http2/write.go` (safe): This is a legitimate portion of the Go standard library's HTTP/2 implementation with no malicious patterns; only minor robustness concerns exist.
- `http2/writesched.go` (safe): Cleared by Jev triage; no further analysis needed
- `http2/writesched_common.go` (safe): Cleared by Jev triage; no further analysis needed
- `http2/writesched_priority_rfc7540.go` (safe): Cleared by Jev triage; no further analysis needed
- `http2/writesched_priority_rfc9218.go` (safe): Cleared by Jev triage; no further analysis needed
- `http2/writesched_random.go` (safe): Cleared by Jev triage; no further analysis needed
- `http2/writesched_roundrobin.go` (safe): Cleared by Jev triage; no further analysis needed
- `icmp/dstunreach.go` (safe): Cleared by Jev triage; no further analysis needed
- `icmp/echo.go` (safe): Cleared by Jev triage; no further analysis needed
- `icmp/endpoint.go` (safe): No malicious patterns detected; this is a standard ICMP PacketConn wrapper from the official golang.org/x/net package with only platform-specific read handling and no exfiltration, obfuscation, or system manipulation.
- `icmp/extension.go` (safe): No malicious patterns detected; the code is standard ICMP extension parsing from the Go standard library ecosystem with no network, file system, process execution, or obfuscation concerns.
- `icmp/helper_posix.go` (safe): No malicious patterns detected; the code is a standard Go library helper for ICMP socket address conversion with no network exfiltration, credential harvesting, obfuscation, or process spawning.
- `icmp/interface.go` (safe): No malicious patterns detected
- `icmp/ipv4.go` (safe): Cleared by Jev triage; no further analysis needed
- `icmp/ipv6.go` (safe): Cleared by Jev triage; no further analysis needed
- `icmp/listen_posix.go` (safe): No malicious patterns detected
- `icmp/listen_stub.go` (safe): Cleared by Jev triage; no further analysis needed
- `icmp/message.go` (safe): Cleared by Jev triage; no further analysis needed
- `icmp/messagebody.go` (safe): Cleared by Jev triage; no further analysis needed
- `icmp/mpls.go` (safe): Cleared by Jev triage; no further analysis needed
- `icmp/multipart.go` (safe): Cleared by Jev triage; no further analysis needed
- `icmp/packettoobig.go` (safe): Cleared by Jev triage; no further analysis needed
- `icmp/paramprob.go` (safe): Cleared by Jev triage; no further analysis needed
- `icmp/sys_freebsd.go` (safe): This is a standard FreeBSD platform initialization file that only reads the OS release date via syscall.SysctlUint32, with no malicious patterns.
- `icmp/timeexceeded.go` (safe): Cleared by Jev triage; no further analysis needed
- `idna/idna.go` (safe): Cleared by Jev triage; no further analysis needed
- `idna/punycode.go` (safe): Cleared by Jev triage; no further analysis needed
- `idna/trie.go` (safe): Cleared by Jev triage; no further analysis needed
- `idna/trieval.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/gate/gate.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/http3/body.go` (safe): No malicious patterns detected
- `internal/http3/conn.go` (safe): No malicious patterns detected; the code implements standard HTTP/3 connection stream handling without exfiltration, credential harvesting, or dynamic execution.
- `internal/http3/doc.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/http3/errors.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/http3/gzip.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/http3/http3.go` (safe): No malicious patterns detected
- `internal/http3/qpack.go` (safe): This code implements QPACK header compression for HTTP/3 and contains no malicious patterns, data exfiltration, credential harvesting, obfuscation, or other security concerns.
- `internal/http3/qpack_decode.go` (safe): No malicious patterns detected; the code is a standard QPACK decoder implementation for HTTP/3 with no network, filesystem, process, or dynamic code execution concerns.
- `internal/http3/qpack_encode.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/http3/qpack_static.go` (safe): No malicious patterns detected; the code is a standard QPACK static table definition with safe indexing and lazy map initialization.
- `internal/http3/quic.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/http3/roundtrip.go` (safe): This is a legitimate Go standard library HTTP/3 transport implementation with no malicious patterns detected.
- `internal/http3/server.go` (safe): No malicious patterns detected; the code is a legitimate HTTP/3 server implementation from the Go standard library with no signs of data exfiltration, credential harvesting, or backdoors.
- `internal/http3/settings.go` (safe): The code implements standard HTTP/3 SETTINGS frame serialization/deserialization with no malicious patterns; only a minor robustness concern about potential panics on invalid varint values.
- `internal/http3/stream.go` (safe): No malicious patterns detected; the code is a legitimate HTTP/3 stream wrapper from the Go standard library.
- `internal/http3/transport.go` (safe): No malicious patterns detected; the code is a standard HTTP/3 transport implementation with no data exfiltration, credential harvesting, obfuscation, or other suspicious behavior.
- `internal/http3/varint.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/httpcommon/ascii.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/httpcommon/headermap.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/httpcommon/request.go` (safe): No malicious patterns detected; the code is standard HTTP header encoding/decoding from Go's x/net library with no network calls, file access, process execution, obfuscation, or credential harvesting.
- `internal/httpsfv/httpsfv.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/iana/const.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/iana/gen.go` (safe): The file is a legitimate Go code generator for IANA constants with expected network fetches and local file writes; no malicious patterns detected.
- `internal/quic/quicwire/wire.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/cmsghdr.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/cmsghdr_bsd.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/cmsghdr_linux_32bit.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/cmsghdr_linux_64bit.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/cmsghdr_solaris_64bit.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/cmsghdr_stub.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/cmsghdr_unix.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/cmsghdr_zos_s390x.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/complete_dontwait.go` (safe): No malicious patterns detected
- `internal/socket/complete_nodontwait.go` (safe): No malicious patterns detected
- `internal/socket/defs_aix.go` (safe): No malicious patterns detected; the file contains only standard cgo type aliases and constants for socket-related C structs, guarded by a build constraint.
- `internal/socket/defs_darwin.go` (safe): No malicious patterns detected
- `internal/socket/defs_dragonfly.go` (safe): No malicious patterns detected
- `internal/socket/defs_freebsd.go` (safe): No malicious patterns detected
- `internal/socket/defs_linux.go` (safe): No malicious patterns detected; this is a standard Go cgo type definition file for socket-related C structs with no executable logic or risky behavior.
- `internal/socket/defs_netbsd.go` (safe): No malicious patterns detected; this is a standard Go cgo type/constant definition file for NetBSD socket structures with no executable logic, network activity, file system access, or dynamic code execution.
- `internal/socket/defs_openbsd.go` (safe): No malicious patterns detected
- `internal/socket/defs_solaris.go` (safe): No malicious patterns detected
- `internal/socket/error_unix.go` (safe): No malicious patterns detected; the code is a standard error-handling helper from the Go standard library's socket package.
- `internal/socket/error_windows.go` (safe): No malicious patterns detected
- `internal/socket/iovec_32bit.go` (safe): The code is a standard, safe use of unsafe.Pointer to build iovec structs for network syscalls; no malicious patterns detected.
- `internal/socket/iovec_solaris_64bit.go` (safe): No malicious patterns detected
- `internal/socket/iovec_stub.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/mmsghdr_stub.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/mmsghdr_unix.go` (safe): No malicious patterns detected; this is legitimate low-level socket handling code from the Go standard library ecosystem with no exfiltration, credential harvesting, obfuscation, or network manipulation.
- `internal/socket/msghdr_bsd.go` (safe): No malicious patterns detected; this is standard Go standard-library-adjacent code for managing socket message headers with legitimate unsafe pointer usage for syscall interop.
- `internal/socket/msghdr_bsdvar.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/msghdr_linux.go` (safe): No malicious patterns detected; this is standard low-level socket msghdr manipulation code from the Go standard library ecosystem using unsafe pointers for legitimate OS syscall structure building.
- `internal/socket/msghdr_linux_32bit.go` (safe): No malicious patterns detected
- `internal/socket/msghdr_linux_64bit.go` (safe): No malicious patterns detected; this is standard Go syscall helper code for building msghdr structures with no external I/O, execution, or data harvesting behavior.
- `internal/socket/msghdr_openbsd.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/msghdr_solaris_64bit.go` (safe): This is standard Go socket message header packing code for Solaris amd64 with no malicious patterns.
- `internal/socket/msghdr_stub.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/msghdr_zos_s390x.go` (safe): No malicious patterns detected in the msghdr packing code for z/OS s390x; it only manipulates memory structures for socket operations without network, filesystem, or process execution.
- `internal/socket/norace.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/race.go` (safe): The code is a standard Go race detector instrumentation file with no malicious patterns; it only uses runtime race detector functions on message buffers under the race build tag.
- `internal/socket/rawconn.go` (safe): No malicious patterns detected; the code is a standard syscall-level socket option wrapper with no exfiltration, obfuscation, or dynamic execution
- `internal/socket/rawconn_mmsg.go` (safe): The code is a legitimate low-level networking implementation from Go's extended socket library with no malicious patterns.
- `internal/socket/rawconn_msg.go` (safe): No malicious patterns detected
- `internal/socket/rawconn_nommsg.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/rawconn_nomsg.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/sys_bsd.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/sys_const_unix.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/sys_linux.go` (safe): No malicious patterns detected
- `internal/socket/sys_linux_386.go` (safe): This file contains standard Go syscall wrappers for recvmmsg/sendmmsg on Linux 386 and exhibits no malicious patterns.
- `internal/socket/sys_linux_amd64.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/sys_linux_arm.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/sys_linux_arm64.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/sys_linux_loong64.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/sys_linux_mips.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/sys_linux_mips64.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/sys_linux_mips64le.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/sys_linux_mipsle.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/sys_linux_ppc.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/sys_linux_ppc64.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/sys_linux_ppc64le.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/sys_linux_riscv64.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/sys_linux_s390x.go` (safe): This file contains standard Go syscall wrappers for recvmmsg/sendmmsg on Linux 386 and exhibits no malicious patterns.
- `internal/socket/sys_netbsd.go` (safe): No malicious patterns detected
- `internal/socket/sys_posix.go` (safe): No malicious patterns detected
- `internal/socket/sys_stub.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/socket/sys_windows.go` (safe): No malicious patterns detected
- `internal/socket/sys_zos_s390x.go` (safe): No malicious patterns detected
- `internal/socket/zsys_aix_ppc64.go` (safe): No malicious patterns detected; the file contains only platform-specific generated struct definitions and constants for AIX networking, with no executable code, imports, or side effects.
- `internal/socket/zsys_darwin_amd64.go` (safe): No malicious patterns detected
- `internal/socket/zsys_darwin_arm64.go` (safe): No malicious patterns detected
- `internal/socket/zsys_dragonfly_amd64.go` (safe): No malicious patterns detected; the file contains only generated cgo struct definitions and size constants for DragonFly BSD socket operations.
- `internal/socket/zsys_freebsd_386.go` (safe): No malicious patterns detected
- `internal/socket/zsys_freebsd_amd64.go` (safe): No malicious patterns detected
- `internal/socket/zsys_freebsd_arm.go` (safe): No malicious patterns detected
- `internal/socket/zsys_freebsd_arm64.go` (safe): No malicious patterns detected
- `internal/socket/zsys_freebsd_riscv64.go` (safe): No malicious patterns detected
- `internal/socket/zsys_linux_386.go` (safe): This is an auto-generated cgo type definition file for low-level socket structures with no executable code or malicious patterns.
- `internal/socket/zsys_linux_amd64.go` (safe): No malicious patterns detected
- `internal/socket/zsys_linux_arm.go` (safe): This is an auto-generated cgo type definition file for low-level socket structures with no executable code or malicious patterns.
- `internal/socket/zsys_linux_arm64.go` (safe): No malicious patterns detected
- `internal/socket/zsys_linux_loong64.go` (safe): No malicious patterns detected

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
