# google.golang.org/grpc@v1.84.0 security report (Go)

- Verdict: **Needs review** (risk level: medium)
- Scanned: 2026-10-05T19:10:09.000Z
- Files reviewed: 545
- Findings: 16 medium, 41 low severity findings
- Report: https://security.togoder.click/go/google.golang.org/grpc
- Source: Togoder Security (https://security.togoder.click), AI source-code review

## Summary

Togoder Security scanned the Go package google.golang.org/grpc@v1.84.0 on Oct 5, 2026. An AI review of 545 source files produced 16 medium, 41 low severity findings. The overall verdict is medium: the findings flag risky but common patterns (dynamic code, unsafe defaults, broad file or network access) rather than confirmed malware.

## Findings

### [medium] Insecure file permissions / privilege escalation risk

Finding ID: `NPS-F9362819EA81`

File: `authz/grpc_authz_server_interceptors.go:149`

The FileWatcherInterceptor reads a policy file from an arbitrary path specified via PolicyFile option. If the process has elevated privileges and the path is attacker-controlled, this could allow reading sensitive files outside the intended package scope. While it is a legitimate feature for loading authz policies, the code does not validate or restrict the file path, potentially enabling information disclosure if an attacker can influence the configuration.

### [medium] Unbounded resource consumption

Finding ID: `NPS-DDB4DEA6B260`

File: `benchmark/worker/main.go:75`

The RunServer/RunClient handlers accept repeated setup requests, each closing previous instances and starting new ones, which could be abused for resource exhaustion if the port is reachable.

### [medium] Network listener on all interfaces

Finding ID: `NPS-4B5CF06F2ADD`

File: `benchmark/worker/main.go:175`

The worker listens on all network interfaces (':<driverPort>') without authentication, allowing any host that can reach the port to control benchmark servers/clients and potentially exhaust resources.

### [medium] File system manipulation outside package scope

Finding ID: `NPS-0B36D64844CB`

File: `binarylog/sink.go:57`

NewTempFileSink creates a temporary file in /tmp using a predictable prefix 'grpcgo_binarylog_*.txt'. Writing potentially sensitive gRPC binary log data (which can include headers, metadata, and message contents) to a world-readable directory like /tmp could lead to information disclosure to other local users or processes on the system.

### [medium] Disabled ALPN verification

Finding ID: `NPS-EE72DFBB9F05`

File: `experimental/credentials/tls.go:166`

The entire package purposefully disables ALPN verification (NewTLSWithALPNDisabled, NewClientTLSFromCertWithALPNDisabled, etc.). ALPN is the mechanism that ensures the negotiated protocol matches expectations; disabling it weakens TLS/HTTP2 security guarantees and can enable protocol downgrade or cross-protocol attacks. The package documentation itself states use is strongly discouraged.

### [medium] TLS verification bypass

Finding ID: `NPS-B59AD0F1589E`

File: `internal/xds/bootstrap/tlscreds/bundle.go:117`

When a SPIFFE bundle map is present, the code disables standard TLS certificate verification (InsecureSkipVerify: true) and delegates validation to a custom verify function. While this is an intentional design for SPIFFE-based trust, misuse or misconfiguration could lead to accepting untrusted certificates if the custom verification logic is flawed or bypassed.

### [medium] Unbounded regex compilation from external input

Finding ID: `NPS-CC5337A3C43E`

File: `internal/xds/matcher/string_matcher.go:123`

StringMatcherFromProto compiles regex patterns received over the network from the xDS management server with regexp.Compile. Malicious or compromised xDS servers can supply pathological patterns that are resource-intensive to compile or execute.

### [medium] ReDoS (Regular Expression Denial of Service) risk

Finding ID: `NPS-A374E9F8DB99`

File: `internal/xds/matcher/string_matcher.go:193`

CompileSafeRegex anchors and compiles user-supplied patterns from xDS protos without complexity limits or timeouts. Crafted regexes (e.g., nested quantifiers like '(a+)+$') can cause catastrophic backtracking, leading to CPU exhaustion and denial of service in the gRPC/xDS control plane or data path when matching strings.

### [medium] Shell command execution from user-controlled input

Finding ID: `NPS-3B1964C5908C`

File: `interop/grpclb_fallback/client_linux.go:108`

runCmd() executes a user-supplied command string via `exec.Command("bash", "-c", command).Run()`. The value comes from the `--induce_fallback_cmd` flag, allowing arbitrary shell command execution when the binary is run. This is typical for an interop/test harness but still represents a command injection surface if the binary is invoked with attacker-controlled flags.

### [medium] Credential exposure in logs

Finding ID: `NPS-5E15D9F9D355`

File: `interop/test_utils.go:313`

Multiple error messages (e.g., DoServiceAccountCreds, DoJWTTokenCreds, DoOauth2TokenCreds, DoPerRPCCreds) log the contents of the service account JSON key file via logger.Fatalf when the username doesn't match. This could leak credential material into logs.

### [medium] Unsafe deserialization

Finding ID: `NPS-051B87E5EA67`

File: `profiling/cmd/local.go:33`

The code uses gob.Decode to deserialize the contents of an arbitrary file path provided via the -snapshot flag. If an attacker can supply a malicious gob-encoded file, this could potentially lead to unexpected behavior or resource exhaustion, although gob is generally considered safer than some other serialization formats. The file path is user-controlled.

### [medium] Arbitrary file write via user-supplied path

Finding ID: `NPS-87F103A055BD`

File: `profiling/cmd/remote.go:55`

The retrieveSnapshot function creates a file using the path provided by the user via *flagSnapshot. An attacker controlling command-line arguments could write a gob-encoded snapshot to an arbitrary location on the filesystem, potentially overwriting sensitive files or placing files in unintended directories.

### [medium] Insecure network transport

Finding ID: `NPS-21A421D32783`

File: `profiling/cmd/remote.go:85`

The code uses grpc.WithTransportCredentials(insecure.NewCredentials()), which disables TLS encryption for the gRPC connection. This means all profiling data and commands sent to the remote server are transmitted in plaintext, potentially exposing sensitive runtime information to attackers on the network.

### [medium] Remote control of profiling subsystem

Finding ID: `NPS-3537850EEFBD`

File: `profiling/service/service.go:88`

The Enable RPC allows any client with access to the gRPC server to remotely enable or disable profiling without authentication or authorization checks. This could be abused to cause resource exhaustion or information disclosure if the profiling service is exposed to untrusted networks.

### [medium] In-memory data exposure via profiling stats

Finding ID: `NPS-418D3C7EE4E9`

File: `profiling/service/service.go:118`

GetStreamStats exposes detailed runtime profiling data (tags, timers, metadata) through an unauthenticated RPC. If the gRPC server is reachable by untrusted parties, this leaks internal timing, call metadata, and potentially sensitive contextual information about RPCs.

### [medium] Environment variable usage

Finding ID: `NPS-73D7A09BAD69`

File: `xds/googledirectpath/googlec2p.go:115`

Reads environment variable C2PResolverTestOnlyTrafficDirectorURI via envconfig to override the Traffic Director URI. If an attacker can control this environment variable, they could redirect traffic to a malicious server. However, this is intended for testing and is guarded by a configuration flag.

### [low] Use of unsafe package

Finding ID: `NPS-A66045E607CB`

File: `authz/grpc_authz_server_interceptors.go:79`

The code uses unsafe.Pointer and atomic.StorePointer/LoadPointer for updating the internal interceptor. While this is a known pattern for lock-free atomic updates, it bypasses Go's type safety and could lead to memory corruption if misused. However, in this context it appears correct and intentional.

### [low] Information leakage via logging

Finding ID: `NPS-BB6C084ED334`

File: `authz/grpc_authz_server_interceptors.go:170`

The full policy content is logged at info level (logger.Infof) when a policy is successfully reloaded. This could expose sensitive authorization rules in logs, which might be accessible to unauthorized parties.

### [low] File System Write Outside Package Scope

Finding ID: `NPS-38DF45E0099D`

File: `benchmark/client/main.go:108`

The program creates CPU and memory profile files directly in `/tmp/` using the user-supplied `-test_name` flag, which could allow writing files to arbitrary paths if the test name contains path traversal sequences (e.g., `../`). This is a local, user-controlled benchmark utility, so the risk is limited.

### [low] Insecure Transport Configuration

Finding ID: `NPS-FF7141D9FB4C`

File: `benchmark/client/main.go:166`

The client connects to the server using insecure transport credentials (`grpc.WithTransportCredentials(insecure.NewCredentials())`). While expected for a local benchmark tool, it would be insecure if used in production or against untrusted networks.

### [low] network listener

Finding ID: `NPS-B7B48E1979E9`

File: `benchmark/server/main.go:70`

The server listens on a TCP port for incoming gRPC connections. This is the intended purpose of the benchmark server and not a security concern.

### [low] file system write

Finding ID: `NPS-A73484090CE7`

File: `benchmark/server/main.go:75`

The program writes CPU and memory profiles to /tmp using a filename derived from the user-supplied -test_name flag. This is expected behavior for a benchmark server and does not indicate malicious intent. However, a non-sanitized test name could theoretically allow path traversal, though this is a local dev tool and not a security boundary.

### [low] Debug pprof endpoint exposure

Finding ID: `NPS-E3B0D6AE8B74`

File: `benchmark/worker/main.go:194`

When pprof_port is specified, an HTTP pprof debug server is started. Although bound to localhost, pprof endpoints can leak runtime details and in some contexts may aid further exploitation.

### [low] Insecure temporary file handling

Finding ID: `NPS-D7959FE53591`

File: `binarylog/sink.go:57`

The function uses os.CreateTemp which is generally safe against race conditions, but the use of a fixed, predictable directory (/tmp) and predictable filename pattern means an attacker with local access could potentially monitor or access these temp files. The sink is explicitly designed to log binary data that may contain sensitive information.

### [low] Environment/platform detection

Finding ID: `NPS-1654E1B5CAC8`

File: `credentials/alts/alts.go`

The code checks whether it is running on Google Cloud Platform (GCE) via googlecloud.OnGCE() before proceeding with ALTS handshakes. This is expected behavior for ALTS credentials and not credential harvesting.

### [low] Network communication

Finding ID: `NPS-7FCEAEA443F0`

File: `credentials/alts/alts.go`

Connects to the ALTS handshaker service at a default GCP-internal address (dns:///metadata.google.internal.:8080) or a user-provided address. This is the documented purpose of the package and not exfiltration.

### [low] init() function usage

Finding ID: `NPS-FAE57B246E2B`

File: `credentials/google/gcp_service_account_identity_credentials.go:78`

The package uses an init() function to initialize global variables (backoff strategy and ID token credentials constructor). This is a standard Go pattern for package initialization and does not perform any suspicious network, file system, or process operations. The initialized functions are only invoked later when explicitly creating credentials.

### [low] ServerName override via OverrideServerName

Finding ID: `NPS-4908A29BECE7`

File: `experimental/credentials/tls.go:116`

OverrideServerName directly mutates c.config.ServerName without validation. If called on a shared config it could redirect certificate verification to an attacker-controlled name. The method is part of the standard TransportCredentials interface, but mutation of the underlying config is a latent risk.

### [low] Potential weak cipher suite inclusion

Finding ID: `NPS-B6F3653E8C39`

File: `experimental/credentials/tls.go:199`

applyDefaults adds all cipher suites reported by tls.CipherSuites() except those explicitly forbidden by RFC 7540 Appendix A. tls.CipherSuites() returns 'secure' suites in modern Go, but the allow-list approach combined with disabled ALPN may still permit suites that are inappropriate for the intended HTTP/2 usage context.

### [low] Unrestricted certificate file read

Finding ID: `NPS-08A657F7242E`

File: `experimental/credentials/tls.go:226`

NewClientTLSFromFileWithALPNDisabled and NewServerTLSFromFileWithALPNDisabled read arbitrary file paths supplied by the caller via os.ReadFile / tls.LoadX509KeyPair. This is expected for credential-loading APIs but could be abused if paths are attacker-influenced; no path sanitization is performed.

### [low] import-time side effect

Finding ID: `NPS-BEFC496AB53A`

File: `grpclog/glogger/glogger.go:29`

The init() function registers a glog-based logger as the global grpclog logger. This is intended package behavior documented in the package comment, not malicious. It has no network, filesystem, credential, or execution capabilities beyond routing log messages.

### [low] Environment variable usage

Finding ID: `NPS-22F854BA866C`

File: `grpclog/grpclog.go:25`

Package documentation references GRPC_GO_LOG_SEVERITY_LEVEL and GRPC_GO_LOG_VERBOSITY_LEVEL environment variables for configuring logging. These are legitimate gRPC logging configuration variables, not credential harvesting.

### [low] Process termination

Finding ID: `NPS-97D8F5DA7146`

File: `grpclog/grpclog.go:79`

Fatal/Fatalf/Fatalln/FatalDepth functions call os.Exit(1). This is standard logging behavior for fatal-level logs in Go's grpclog package, not a backdoor or malicious process spawn.

### [low] Code runs at import time

Finding ID: `NPS-66001C8DDBDC`

File: `internal/binarylog/binarylog.go:76`

The init() function executes automatically when the package is imported, reading environment variables and initializing the global binary logger. While this is standard Go practice and the action is benign (only configuration parsing), it does constitute import-time code execution.

### [low] Environment variable harvesting

Finding ID: `NPS-34A5DDFCB214`

File: `internal/binarylog/binarylog.go:78`

The init() function reads the GRPC_BINARY_LOG_FILTER environment variable at import time and uses it to configure binary logging behavior. This is a legitimate gRPC feature for logging filter configuration, but it means any process importing this package will read this environment variable at startup.

### [low] Environment variable controlled security behavior

Finding ID: `NPS-6C23BDBD4D58`

File: `internal/credentials/xds/handshake_info.go`

The code checks envconfig.XDSSNIEnabled to conditionally change SNI and SAN validation behavior. This is not credential harvesting or exfiltration; it is a standard gRPC xDS feature flag. No malicious environment variable reading for secrets was observed.

### [low] Testing hook registered in init()

Finding ID: `NPS-B97EEF960015`

File: `internal/credentials/xds/handshake_info.go:34`

The init() function sets internal.GetXDSHandshakeInfoForTesting = HandshakeInfoFromAttributes. This runs at package import time but only wires an internal testing hook and does not perform any network, filesystem, or process operations. It is benign for this gRPC package.

### [low] Custom certificate verification with InsecureSkipVerify

Finding ID: `NPS-2211735B88E3`

File: `internal/credentials/xds/handshake_info.go:239`

The client-side TLS config sets InsecureSkipVerify to true, disabling Go's built-in hostname and certificate chain verification. While this is intentional to perform custom SAN verification via VerifyPeerCertificate, it is a security-sensitive pattern that could allow MITM if the custom verification logic has flaws. In this code the custom function does chain verification and SAN matching, so it is not malicious.

### [low] Environment variable reading

Finding ID: `NPS-C1394415DBC9`

File: `internal/envconfig/envconfig.go`

This code reads numerous GRPC_* environment variables to configure gRPC behavior. This is the intended, documented purpose of the file. The environment variables are configuration knobs specific to gRPC (TXT service config, ring hash cap, ALTS handshake limits, header list size, etc.) and do not involve harvesting credentials, tokens, or secrets.

### [low] Package-level variable initialization

Finding ID: `NPS-25894A051D65`

File: `internal/envconfig/envconfig.go`

The file uses package-level var initialization to read environment variables at import time. This is normal Go practice for configuration and matches the file's stated purpose. The values are parsed safely via strconv.ParseUint and string comparisons; no external calls, file access, or code execution occur.

### [low] standard protobuf initialization code

Finding ID: `NPS-1A6E18B45C6B`

File: `internal/proto/grpc_lookup_v1/rls_config.pb.go`

The init() function performs standard protobuf registration and descriptor building only. No external calls, file I/O, network access, or process spawning occurs.

### [low] unsafe pointer usage for gzip compression

Finding ID: `NPS-6E7CA33C7713`

File: `internal/proto/grpc_lookup_v1/rls_config.pb.go`

Uses unsafe.Slice/unsafe.StringData to compress the embedded proto descriptor. This is standard generated code from protoc-gen-go for efficiency; the data is a static compile-time constant, not attacker-controlled.

### [low] File system manipulation

Finding ID: `NPS-2349B6BF63EE`

File: `internal/testutils/xds/e2e/bootstrap.go`

The code creates temporary directories and copies certificate/key files into them for use in end-to-end tests. This is normal test utility behavior and does not access sensitive user files or locations outside the test scope.

### [low] Use of os.ModePerm

Finding ID: `NPS-8278288386BD`

File: `internal/testutils/xds/e2e/bootstrap.go`

Files are written with permission 0777 (os.ModePerm), which is overly permissive. However, these are temporary test files in a temporary directory and not a security risk in this context.

### [low] Environment variable gating

Finding ID: `NPS-16EC04B3F55E`

File: `internal/xds/bootstrap/tlscreds/bundle.go:62`

The SPIFFE trust bundle map file functionality is gated behind the environment variable XDSSPIFFEEnabled. If not explicitly enabled, the feature is disabled by clearing the config field. This is not malicious but could be used to conditionally activate functionality based on environment, which might be unexpected in a security-sensitive context.

### [low] weak parsing with Sscanf

Finding ID: `NPS-269ECFB133C1`

File: `internal/xds/xds.go:96`

LocalityFromString uses fmt.Sscanf with %q format specifiers to parse locality strings. While not a direct security vulnerability, format-string-based parsing can be fragile and may not handle malformed or adversarial inputs robustly. No direct exploit is evident.

### [low] init function execution at import time

Finding ID: `NPS-EDE614A6D6C2`

File: `internal/xds/xds.go:117`

The init() function runs automatically when the package is imported. It registers a callback function via internal.AddressToTelemetryLabels. While this is standard Go practice for package initialization and the assignment itself is benign, it constitutes top-level code execution at import time that modifies global state. In this specific case the callback only returns telemetry labels derived from resolver addresses, but init() functions are a common vector for malicious code and warrant examination.

### [low] Dynamic import / balancer registration

Finding ID: `NPS-173E850CE76F`

File: `interop/grpclb_fallback/client_linux.go:30`

Imports with blank identifiers (`_ "google.golang.org/grpc/balancer/grpclb"` and `_ "google.golang.org/grpc/xds/googledirectpath"`) trigger side-effect init() functions in those packages. This is expected gRPC behavior, but blank-import side effects are a common vector for hidden initialization logic.

### [low] Raw socket option manipulation

Finding ID: `NPS-92906130C709`

File: `interop/grpclb_fallback/client_linux.go:83`

dialTCPUserTimeout uses syscall.RawConn.Control to set TCP_USER_TIMEOUT via unix.SetsockoptInt, and calls errorLog.Fatalf on error. Uses Fatal inside a Control callback (goroutine context) rather than returning the error, which can terminate the process unexpectedly. Not malicious, but low-level socket manipulation warrants noting.

### [low] insecure gRPC connection

Finding ID: `NPS-1D7E44D49D18`

File: `interop/stress/metrics_client/main.go:71`

The client uses insecure.NewCredentials() to connect to the metrics server, meaning the connection is unencrypted. This is a security best-practice concern but not a malicious pattern; it is common in test/interop tooling.

### [low] Test-only package with fatal exits

Finding ID: `NPS-152CD413E0D0`

File: `interop/test_utils.go`

The package is explicitly for gRPC interop testing and uses logger.Fatalf extensively rather than returning errors. If imported and invoked outside a test context, it would terminate the process. Not malicious, but unsafe for production use.

### [low] Credential file reading

Finding ID: `NPS-57CA5C6B8459`

File: `interop/test_utils.go:285`

The getServiceAccountJSONKey function reads arbitrary files from the filesystem based on a parameter passed at runtime (serviceAccountKeyFile). It is used to read Google service account JSON keys, which contain private credentials. This is legitimate for interop testing but represents a pattern that reads sensitive credential files from disk.

### [low] global mutable state

Finding ID: `NPS-BD9F112E1C64`

File: `mem/buffer_pool.go:43`

The package maintains a package-level variable defaultBufferPool that can be arbitrarily reassigned via internal.SetDefaultBufferPool. If an attacker gains control of any dependency that imports this package, they could replace the buffer pool with a malicious implementation (e.g., one that returns buffers containing attacker-controlled data or that exfiltrates data via Put). This is a latent supply-chain risk rather than a direct malicious pattern.

### [low] init-time code execution

Finding ID: `NPS-0AA76F8FC6A2`

File: `mem/buffer_pool.go:47`

The init() function runs automatically at import time and initializes a default buffer pool. It also registers a callback (internal.SetDefaultBufferPool) that allows replacing the global default buffer pool. While the code itself is not malicious, the init() pattern is a red flag because such hooks can be abused to inject behavior at import time. The SetDefaultBufferPool hook could be repurposed by a malicious package to replace the pool with one that leaks or corrupts data.

### [low] import-time code execution

Finding ID: `NPS-E81277627BE8`

File: `orca/orca.go:52`

The init() function registers a parser with the balancer load subsystem. This is expected behavior for a library that needs to register itself, and the parser only reads metadata to generate load reports locally. There is no network, filesystem, or process activity.

### [low] Network request to metadata server

Finding ID: `NPS-C37CC8A535DA`

File: `xds/googledirectpath/googlec2p.go:56`

Makes HTTP requests to the GCE metadata server (http://metadata.google.internal) to retrieve instance zone and IPv6 capabilities. While this is a standard GCE metadata call, it could be abused to leak instance metadata if the code were modified by an attacker, though the current usage is legitimate.

### [low] Dynamic resolver configuration

Finding ID: `NPS-68D431CE8F1F`

File: `xds/googledirectpath/googlec2p.go:140`

Constructs xDS bootstrap configuration dynamically based on environment (GCE detection, metadata, universe domain) and creates a gRPC resolver. This dynamic behavior could be exploited if an attacker can influence the environment, but the code follows expected patterns for the library.

## Files reviewed

- `authz/grpc_authz_server_interceptors.go` (medium): The code is a legitimate gRPC authorization interceptor with no clear malicious intent, but it has minor security concerns related to file path handling, logging of policy content, and unsafe pointer usage.
- `benchmark/worker/main.go` (medium): The benchmark worker is a legitimate gRPC testing utility but exposes an unauthenticated network control interface and optional pprof debug endpoint, posing resource exhaustion and information disclosure risks if reachable by untrusted parties.
- `binarylog/sink.go` (medium): The code is part of the official gRPC-Go library and appears benign, but it writes binary log data (potentially containing sensitive information) to temporary files in /tmp, which presents a moderate information disclosure risk if used in multi-user environments.
- `experimental/credentials/tls.go` (medium): This is a legitimate gRPC-Go experimental credentials package, but its deliberate disabling of ALPN verification weakens TLS security guarantees and the API surface introduces minor risks around server-name override and arbitrary file path reads.
- `internal/binarylog/binarylog.go` (medium): This appears to be a legitimate gRPC binary logging implementation with no malicious patterns; the only concerns are benign import-time environment variable reading and initialization typical of Go libraries.
- `internal/xds/bootstrap/tlscreds/bundle.go` (medium): The code implements mTLS credentials for xDS with SPIFFE support, but disables standard TLS verification when using SPIFFE bundles, relying on custom verification logic, which poses a medium risk if misconfigured.
- `internal/xds/matcher/string_matcher.go` (medium): No overt malicious code (no exfiltration, credential harvesting, backdoors, or dynamic execution) was found; the only concerns are standard ReDoS and resource-exhaustion risks inherent in compiling and evaluating externally supplied regular expressions from xDS configuration.
- `internal/xds/xds.go` (medium): This is legitimate gRPC xDS utility code with no malicious patterns; the only notable item is a standard Go init() function that registers an internal callback, which is benign here but is a common pattern for import-time code execution.
- `interop/grpclb_fallback/client_linux.go` (medium): This is a legitimate gRPC interop test client from the official grpc-go repository; the only notable concern is intentional shell command execution via the --induce_fallback_cmd flag, which is standard for its test-harness purpose but should be treated with caution.
- `interop/test_utils.go` (medium): This is a legitimate gRPC interop testing utility from the official grpc-go repository; it reads credential files and logs them on failure, but exhibits no malicious exfiltration, backdoor, or obfuscation patterns.
- `mem/buffer_pool.go` (medium): The code is a legitimate gRPC buffer pool implementation with no malicious patterns, but its init-time global registration hook and mutable default pool present low-severity supply-chain concerns.
- `profiling/cmd/local.go` (medium): The code appears to be a legitimate gRPC profiling tool with no obvious malicious patterns, but it deserializes a user-specified file using gob, which could be a security concern if untrusted input is processed.
- `profiling/cmd/remote.go` (medium): The Go file is a legitimate gRPC profiling client but has security weaknesses: it uses insecure gRPC transport (no TLS) and writes a snapshot file to a user-controlled path, which could lead to plaintext data exposure or arbitrary file writes.
- `profiling/service/service.go` (medium): No malicious code patterns were found, but the profiling service exposes unauthenticated RPCs that allow remote enabling/disabling of profiling and retrieval of internal runtime statistics, which could be abused if the server is exposed.
- `xds/googledirectpath/googlec2p.go` (medium): The code appears to be a legitimate gRPC resolver for Google DirectPath, with expected metadata server calls and environment variable usage; no malicious patterns were found, but potential misuse of environment variables and metadata endpoints warrants a warning.
- `admin/admin.go` (safe): No malicious patterns detected; the code is a legitimate gRPC admin service registration package.
- `attributes/attributes.go` (safe): Cleared by Jev triage; no further analysis needed
- `authz/audit/audit_logger.go` (safe): Cleared by Jev triage; no further analysis needed
- `authz/audit/stdout/stdout_logger.go` (safe): Legitimate gRPC authorization audit logger that writes audit events to stdout; no malicious patterns detected.
- `authz/rbac_translator.go` (safe): No malicious patterns detected; the file is a legitimate gRPC authz policy translator with no exfiltration, credential harvesting, dynamic execution, or other red flags.
- `backoff.go` (safe): Cleared by Jev triage; no further analysis needed
- `backoff/backoff.go` (safe): Cleared by Jev triage; no further analysis needed
- `balancer/balancer.go` (safe): This is the official gRPC-Go balancer package containing standard interfaces and registration logic with no malicious patterns detected.
- `balancer/base/balancer.go` (safe): No malicious patterns detected; this is the standard gRPC-Go base balancer implementation with no external network calls, credential access, or dynamic code execution.
- `balancer/base/base.go` (safe): Cleared by Jev triage; no further analysis needed
- `balancer/conn_state_evaluator.go` (safe): Cleared by Jev triage; no further analysis needed
- `balancer/endpointsharding/endpointsharding.go` (safe): No malicious patterns detected; the code is a legitimate gRPC load balancing policy with no data exfiltration, credential harvesting, obfuscation, or other security concerns.
- `balancer/grpclb/grpc_lb_v1/load_balancer.pb.go` (safe): This is a standard auto-generated protobuf file from the official gRPC library containing only message definitions and serialization metadata with no malicious patterns.
- `balancer/grpclb/grpc_lb_v1/load_balancer_grpc.pb.go` (safe): Cleared by Jev triage; no further analysis needed
- `balancer/grpclb/grpclb.go` (safe): No malicious patterns detected; the file is the official gRPC-Go grpclb balancer implementation with standard network, resolver, and credential handling consistent with its documented purpose.
- `balancer/grpclb/grpclb_config.go` (safe): Cleared by Jev triage; no further analysis needed
- `balancer/grpclb/grpclb_picker.go` (safe): Cleared by Jev triage; no further analysis needed
- `balancer/grpclb/grpclb_remote_balancer.go` (safe): This is a legitimate gRPC load balancer implementation from the official Google gRPC-Go library with no malicious patterns detected.
- `balancer/grpclb/grpclb_util.go` (safe): No malicious patterns detected; the code implements a gRPC load balancer SubConn cache with standard synchronization and lifecycle handling.
- `balancer/grpclb/state/state.go` (safe): Cleared by Jev triage; no further analysis needed
- `balancer/lazy/lazy.go` (safe): No malicious patterns detected; this is a legitimate gRPC lazy load balancer implementation from the official gRPC-Go library.
- `balancer/leastrequest/leastrequest.go` (safe): This is a standard gRPC least-request load balancer implementation with no malicious patterns, external calls, or suspicious behavior.
- `balancer/pickfirst/internal/internal.go` (safe): Cleared by Jev triage; no further analysis needed
- `balancer/pickfirst/pickfirst.go` (safe): No malicious patterns detected; this is a legitimate gRPC pick_first load balancer implementation with only standard library and gRPC-internal package imports and no suspicious behavior.
- `balancer/randomsubsetting/randomsubsetting.go` (safe): Cleared by Jev triage; no further analysis needed
- `balancer/ringhash/config.go` (safe): No malicious patterns detected; the code is a standard gRPC ringhash load balancer configuration parser with proper input validation.
- `balancer/ringhash/logging.go` (safe): Cleared by Jev triage; no further analysis needed
- `balancer/ringhash/picker.go` (safe): No malicious patterns detected; the code implements gRPC ringhash load balancing logic with no exfiltration, credential harvesting, obfuscation, or process execution.
- `balancer/ringhash/ring.go` (safe): Cleared by Jev triage; no further analysis needed
- `balancer/ringhash/ringhash.go` (safe): This is a legitimate gRPC ring hash balancer implementation from the official google.golang.org/grpc package with no malicious patterns detected.
- `balancer/rls/balancer.go` (safe): No malicious patterns detected in the gRPC RLS balancer implementation; all imports and operations are standard for its intended load-balancing functionality.
- `balancer/rls/cache.go` (safe): Cleared by Jev triage; no further analysis needed
- `balancer/rls/child_policy.go` (safe): No malicious patterns detected; the code is a legitimate gRPC balancer child policy wrapper with reference counting and atomic state management.
- `balancer/rls/config.go` (safe): No malicious patterns detected; the file is a legitimate gRPC RLS balancer config parser with proper input validation and no external data exfiltration, credential harvesting, dynamic code execution, or backdoor behavior.
- `balancer/rls/control_channel.go` (safe): This is legitimate gRPC RLS control channel code from the official grpc-go library with no malicious patterns, no credential harvesting, no exfiltration, and no obfuscation.
- `balancer/rls/internal/adaptive/adaptive.go` (safe): No malicious patterns detected; this is a legitimate adaptive throttling implementation from the gRPC-Go library with no external network calls, credential access, code execution, or obfuscation.
- `balancer/rls/internal/adaptive/lookback.go` (safe): Cleared by Jev triage; no further analysis needed
- `balancer/rls/internal/keys/builder.go` (safe): Cleared by Jev triage; no further analysis needed
- `balancer/rls/picker.go` (safe): No malicious patterns detected; the code is a legitimate part of gRPC's Route Lookup Service balancer with no security concerns.
- `balancer/roundrobin/roundrobin.go` (safe): This is a legitimate gRPC round-robin balancer implementation with no malicious patterns detected.
- `balancer/subconn.go` (safe): Cleared by Jev triage; no further analysis needed
- `balancer/weightedroundrobin/balancer.go` (safe): This is a standard gRPC weighted round-robin load balancer implementation with no malicious patterns, external data exfiltration, credential harvesting, or suspicious behavior detected.
- `balancer/weightedroundrobin/config.go` (safe): Cleared by Jev triage; no further analysis needed
- `balancer/weightedroundrobin/internal/internal.go` (safe): No malicious patterns detected; the code only defines test hooks for a gRPC balancer, with no network, file, process, or obfuscated behavior.
- `balancer/weightedroundrobin/logging.go` (safe): Cleared by Jev triage; no further analysis needed
- `balancer/weightedroundrobin/scheduler.go` (safe): Cleared by Jev triage; no further analysis needed
- `balancer/weightedtarget/logging.go` (safe): Cleared by Jev triage; no further analysis needed
- `balancer/weightedtarget/weightedaggregator/aggregator.go` (safe): Cleared by Jev triage; no further analysis needed
- `balancer/weightedtarget/weightedtarget.go` (safe): No malicious patterns detected; this is a legitimate gRPC weighted target balancer implementation.
- `balancer/weightedtarget/weightedtarget_config.go` (safe): Cleared by Jev triage; no further analysis needed
- `balancer_wrapper.go` (safe): No malicious patterns detected; this is standard gRPC balancer wrapper code with legitimate networking and state management logic.
- `benchmark/benchmain/main.go` (safe): No malicious patterns detected; the code is a standard gRPC benchmarking tool with legitimate file I/O for profiling and results, and no data exfiltration, credential harvesting, obfuscation, or suspicious process execution.
- `benchmark/benchmark.go` (safe): This is a legitimate gRPC benchmark package from the official google.golang.org/grpc repository with no malicious patterns detected.
- `benchmark/benchresult/main.go` (safe): Cleared by Jev triage; no further analysis needed
- `benchmark/client/main.go` (safe): The code is a legitimate gRPC benchmark client with no malicious patterns; the only minor concerns are insecure transport usage and profiling files written to /tmp based on user input.
- `benchmark/flags/flags.go` (safe): Cleared by Jev triage; no further analysis needed
- `benchmark/latency/latency.go` (safe): No malicious patterns detected; the code is a benign gRPC latency injection benchmark utility.
- `benchmark/server/main.go` (safe): The code is a legitimate gRPC benchmarking server with no malicious patterns; it only performs profiling and listens on a local port.
- `benchmark/stats/curve.go` (safe): Cleared by Jev triage; no further analysis needed
- `benchmark/stats/histogram.go` (safe): Cleared by Jev triage; no further analysis needed
- `benchmark/stats/stats.go` (safe): Cleared by Jev triage; no further analysis needed
- `benchmark/worker/benchmark_client.go` (safe): This is a standard gRPC benchmark client from the official google.golang.org/grpc repository with no malicious patterns; all network, file, and process usage is consistent with its benchmarking purpose.
- `benchmark/worker/benchmark_server.go` (safe): No malicious patterns detected; the file is part of the official gRPC-Go benchmark worker and only implements a TLS-capable benchmark server with no exfiltration, credential harvesting, obfuscation, or process spawning.
- `binarylog/grpc_binarylog_v1/binarylog.pb.go` (safe): This is a standard protoc-gen-go generated file for gRPC binary logging protobuf definitions, containing only boilerplate message types, enum definitions, and protobuf reflection registration with no malicious patterns.
- `call.go` (safe): No malicious patterns detected; the code is standard gRPC client invocation logic from the official gRPC-Go package with no exfiltration, obfuscation, credential harvesting, or other suspicious behavior.
- `channelz/channelz.go` (safe): No malicious patterns detected; the file only re-exports an identifier type from an internal gRPC package.
- `channelz/grpc_channelz_v1/channelz_grpc.pb.go` (safe): Cleared by Jev triage; no further analysis needed
- `channelz/internal/protoconv/channel.go` (safe): Cleared by Jev triage; no further analysis needed
- `channelz/internal/protoconv/server.go` (safe): Cleared by Jev triage; no further analysis needed
- `channelz/internal/protoconv/socket.go` (safe): No malicious patterns detected; this is a legitimate gRPC channelz protobuf conversion utility with no external data transmission, credential harvesting, or code execution.
- `channelz/internal/protoconv/sockopt_linux.go` (safe): No malicious patterns detected
- `channelz/internal/protoconv/sockopt_nonlinux.go` (safe): Cleared by Jev triage; no further analysis needed
- `channelz/internal/protoconv/subchannel.go` (safe): Cleared by Jev triage; no further analysis needed
- `channelz/internal/protoconv/util.go` (safe): Cleared by Jev triage; no further analysis needed
- `channelz/service/service.go` (safe): No malicious patterns detected; code is a legitimate gRPC channelz service implementation from the official google.golang.org/grpc module.
- `clientconn.go` (safe): No malicious patterns detected
- `clientconn_disconnect_reason_noplan9.go` (safe): No malicious patterns detected
- `clientconn_disconnect_reason_plan9.go` (safe): Cleared by Jev triage; no further analysis needed
- `codec.go` (safe): Cleared by Jev triage; no further analysis needed
- `codes/code_string.go` (safe): Cleared by Jev triage; no further analysis needed
- `codes/codes.go` (safe): Cleared by Jev triage; no further analysis needed
- `connectivity/connectivity.go` (safe): Cleared by Jev triage; no further analysis needed
- `credentials/alts/alts.go` (safe): This is a legitimate gRPC ALTS credentials implementation with no malicious patterns; network connections and platform checks are inherent to its documented security functionality.
- `credentials/alts/internal/authinfo/authinfo.go` (safe): Cleared by Jev triage; no further analysis needed
- `credentials/alts/internal/common.go` (safe): Cleared by Jev triage; no further analysis needed
- `credentials/alts/internal/conn/aeadrekey.go` (safe): This is a legitimate gRPC ALTS rekey AEAD implementation with no malicious patterns; it uses standard cryptographic primitives for encryption and key derivation without any exfiltration, backdoors, or suspicious behavior.
- `credentials/alts/internal/conn/aes128gcm.go` (safe): Cleared by Jev triage; no further analysis needed
- `credentials/alts/internal/conn/aes128gcmrekey.go` (safe): This file contains standard cryptographic implementation for gRPC ALTS record layer using AES128-GCM with rekeying, with no malicious patterns, network calls, process spawning, file system access, or dynamic code execution.
- `credentials/alts/internal/conn/common.go` (safe): Cleared by Jev triage; no further analysis needed
- `credentials/alts/internal/conn/counter.go` (safe): Cleared by Jev triage; no further analysis needed
- `credentials/alts/internal/conn/record.go` (safe): This is a legitimate gRPC ALTS record protocol implementation with no malicious patterns detected.
- `credentials/alts/internal/conn/utils.go` (safe): Cleared by Jev triage; no further analysis needed
- `credentials/alts/internal/handshaker/handshaker.go` (safe): No malicious patterns detected; the code is a legitimate gRPC ALTS handshaker implementation with proper bounds checking and no data exfiltration or backdoors.
- `credentials/alts/internal/handshaker/service/service.go` (safe): No malicious patterns detected; the code manages ALTS handshaker gRPC connections using standard connection pooling and insecure credentials only for a local VM-to-hypervisor channel.
- `credentials/alts/internal/proto/grpc_gcp/altscontext.pb.go` (safe): This is a standard protoc-gen-go generated file for ALTS context definitions with no malicious patterns such as exfiltration, credential harvesting, obfuscation, or dynamic execution.
- `credentials/alts/internal/proto/grpc_gcp/handshaker.pb.go` (safe): No malicious patterns detected; this is a standard protoc-generated Go file defining gRPC ALTS handshaker protobuf types with no executable network, file system, or process operations.
- `credentials/alts/internal/proto/grpc_gcp/handshaker_grpc.pb.go` (safe): Cleared by Jev triage; no further analysis needed
- `credentials/alts/internal/proto/grpc_gcp/transport_security_common.pb.go` (safe): This is standard protoc-gen-go generated code for gRPC ALTS transport security protobuf definitions with no malicious patterns detected.
- `credentials/alts/internal/testutil/testutil.go` (safe): Cleared by Jev triage; no further analysis needed
- `credentials/alts/utils.go` (safe): Cleared by Jev triage; no further analysis needed
- `credentials/credentials.go` (safe): Cleared by Jev triage; no further analysis needed
- `credentials/google/gcp_service_account_identity_credentials.go` (safe): The code implements standard GCP service account ID token credentials using Google's auth library and metadata server; no malicious patterns such as exfiltration, credential harvesting, obfuscation, shell execution, or unauthorized file access were detected.
- `credentials/google/google.go` (safe): This is the standard gRPC-Go Google credentials implementation, which uses well-known authentication mechanisms (ADC, ALTS, TLS) without any malicious patterns.
- `credentials/google/internal/internal.go` (safe): No malicious patterns detected; the file only declares internal package variables and function pointers for credential handling without any suspicious behavior.
- `credentials/google/xds.go` (safe): No malicious patterns detected; code is a legitimate gRPC transport credentials implementation for Google Cloud xDS with standard TLS/ALTS selection logic.
- `credentials/insecure/insecure.go` (safe): Cleared by Jev triage; no further analysis needed
- `credentials/jwt/doc.go` (safe): No malicious patterns detected; this is a standard package documentation file for gRPC JWT credentials with no executable code.
- `credentials/jwt/file_reader.go` (safe): No malicious patterns detected; the code is a legitimate JWT file reader that only parses tokens and checks expiration without any suspicious behavior.
- `credentials/jwt/token_file_call_creds.go` (safe): No malicious patterns detected; the code is a legitimate gRPC JWT token file credentials implementation with standard token caching, backoff, and file reading logic.
- `credentials/local/local.go` (safe): Cleared by Jev triage; no further analysis needed
- `credentials/oauth/oauth.go` (safe): No malicious patterns detected; this is the official gRPC OAuth credentials implementation with expected behavior and no exfiltration, obfuscation, or backdoor code.
- `credentials/sts/sts.go` (safe): No malicious patterns detected in the STS credentials implementation; code is a legitimate gRPC library token exchange mechanism.
- `credentials/tls.go` (safe): No malicious patterns detected; this is the standard gRPC-Go TLS credentials implementation with no exfiltration, credential harvesting, obfuscation, or suspicious behavior.
- `credentials/tls/certprovider/distributor.go` (safe): Cleared by Jev triage; no further analysis needed
- `credentials/tls/certprovider/pemfile/builder.go` (safe): No malicious patterns detected
- `credentials/tls/certprovider/pemfile/watcher.go` (safe): No malicious patterns detected; the code is a legitimate gRPC certificate provider plugin for watching PEM files.
- `credentials/tls/certprovider/provider.go` (safe): No malicious patterns detected
- `credentials/tls/certprovider/store.go` (safe): No malicious patterns detected
- `credentials/xds/xds.go` (safe): No malicious patterns detected; the code is a legitimate gRPC xDS credentials implementation with standard TLS handshaking and no suspicious behaviors.
- `dialoptions.go` (safe): Cleared by Jev triage; no further analysis needed
- `doc.go` (safe): No malicious patterns detected
- `encoding/encoding.go` (safe): No malicious patterns detected in this standard gRPC encoding registration package.
- `encoding/encoding_v2.go` (safe): Cleared by Jev triage; no further analysis needed
- `encoding/gzip/gzip.go` (safe): No malicious patterns detected; the code implements a standard gRPC gzip compressor with no exfiltration, credential harvesting, obfuscation, or other red flags.
- `encoding/internal/internal.go` (safe): No malicious patterns detected; the file only declares a testing variable and contains no executable code or suspicious behavior.
- `encoding/proto/proto.go` (safe): No malicious patterns detected in the gRPC proto codec implementation; the code performs standard protobuf marshaling/unmarshaling registration and contains no exfiltration, credential harvesting, obfuscation, or process execution.
- `experimental/balancer/hostname/hostname.go` (safe): Cleared by Jev triage; no further analysis needed
- `experimental/balancer/weight/weight.go` (safe): Cleared by Jev triage; no further analysis needed
- `experimental/credentials/internal/spiffe.go` (safe): Cleared by Jev triage; no further analysis needed
- `experimental/credentials/internal/syscallconn.go` (safe): No malicious patterns detected; the code is a straightforward syscall.Conn wrapper with no network, filesystem, process, or dynamic execution behavior.
- `experimental/experimental.go` (safe): No malicious patterns detected; the file only exposes experimental gRPC buffer pool and compressor configuration APIs via internal function indirection.
- `experimental/opentelemetry/trace_options.go` (safe): Cleared by Jev triage; no further analysis needed
- `experimental/stats/metricregistry.go` (safe): The file is a legitimate gRPC metrics registry implementation with no malicious patterns detected.
- `experimental/stats/metrics.go` (safe): Cleared by Jev triage; no further analysis needed
- `experimental/stats/telemetry/labels.go` (safe): No malicious patterns detected
- `grpclog/component.go` (safe): Cleared by Jev triage; no further analysis needed
- `grpclog/glogger/glogger.go` (safe): This is the legitimate gRPC-Go glog logger adapter; it only wires glog into grpclog via init() and contains no malicious patterns.
- `grpclog/grpclog.go` (safe): This is the standard gRPC Go logging package; no malicious patterns, exfiltration, or backdoors detected.
- `grpclog/internal/grpclog.go` (safe): Cleared by Jev triage; no further analysis needed
- `grpclog/internal/logger.go` (safe): Cleared by Jev triage; no further analysis needed
- `grpclog/internal/loggerv2.go` (safe): Cleared by Jev triage; no further analysis needed
- `grpclog/logger.go` (safe): No malicious patterns detected in the grpclog/logger.go file; it is a standard gRPC logging interface wrapper with no suspicious behavior.
- `grpclog/loggerv2.go` (safe): No malicious patterns detected; this is a legitimate gRPC logging configuration file that reads standard log level environment variables and writes to stderr or discard, with no network, exec, or exfiltration behavior.
- `health/client.go` (safe): No malicious patterns detected
- `health/grpc_health_v1/health.pb.go` (safe): No malicious patterns detected in this standard gRPC health check protobuf-generated Go file.
- `health/grpc_health_v1/health_grpc.pb.go` (safe): No malicious patterns detected
- `health/logging.go` (safe): Cleared by Jev triage; no further analysis needed
- `health/producer.go` (safe): No malicious patterns detected; the code is a legitimate gRPC health checking producer with standard Go patterns and no suspicious behavior.
- `health/server.go` (safe): Cleared by Jev triage; no further analysis needed
- `interceptor.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/admin/admin.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/backoff/backoff.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/balancer/gracefulswitch/config.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/balancer/gracefulswitch/gracefulswitch.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/balancer/nop/nop.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/balancer/stub/stub.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/balancergroup/balancergroup.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/balancergroup/balancerstateaggregator.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/balancerload/load.go` (safe): No malicious patterns detected
- `internal/binarylog/binarylog_testutil.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/binarylog/env_config.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/binarylog/method_logger.go` (safe): No malicious patterns detected
- `internal/binarylog/sink.go` (safe): No malicious patterns detected; the file is a legitimate gRPC binary logging sink implementation with no exfiltration, credential harvesting, obfuscation, or shell execution.
- `internal/buffer/unbounded.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/cache/timeoutCache.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/channelz/channel.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/channelz/channelmap.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/channelz/funcs.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/channelz/logging.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/channelz/server.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/channelz/socket.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/channelz/subchannel.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/channelz/syscall_linux.go` (safe): No malicious patterns detected; the code only reads socket options from a provided connection using standard syscall interfaces for legitimate channelz monitoring purposes.
- `internal/channelz/syscall_nonlinux.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/channelz/trace.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/credentials/credentials.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/credentials/spiffe.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/credentials/spiffe/spiffe.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/credentials/syscallconn.go` (safe): No malicious patterns detected
- `internal/credentials/util.go` (safe): Cleared by Jev triage; no further analysis needed
- `internal/credentials/xds/handshake_info.go` (safe): The code is a legitimate gRPC xDS credentials implementation with no malicious exfiltration, credential harvesting, obfuscation, backdoor, or arbitrary code execution patterns; only standard security-sensitive TLS custom verification logic is present.
- `internal/envconfig/envconfig.go` (safe): Legitimate gRPC environment configuration code with no malicious patterns detected.
- `internal/envconfig/observability.go` (safe): No malicious patterns detected
- `internal/envconfig/xds.go` (safe): No malicious patterns detected; the file only reads environment variables for gRPC xDS configuration with standard, documented feature flags.
- `internal/experimental.go` (safe): Cleared by Jev triage; no further analysis needed

AI analysis is guidance, not a guarantee. Methodology: https://security.togoder.click/methodology
