Evaluating Cryptographic API Misuse Detectors for Go

Fuente: arXiv
Salvato in:
Dettagli Bibliografici
Autori principali: Andersson, Vivi, Monperrus, Martin
Natura: Preprint
Pubblicazione: 2026
Soggetti:
Accesso online:
Tags: Aggiungi Tag
Nessun Tag, puoi essere il primo ad aggiungerne!!
_version_ 1866913064543059968
author Andersson, Vivi
Monperrus, Martin
author_facet Andersson, Vivi
Monperrus, Martin
contents Cryptographic API misuse represents a critical vulnerability class that undermines the security foundations of modern software. Yet, it remains largely unexplored in Go despite its dominance in security-critical infrastructure. This paper presents the first comprehensive study of cryptographic API misuse detection in Go, identifying and analyzing 4 state-of-the-art tools (CodeQL, Gopher, Gosec, and Snyk Code) and establishing a consolidated taxonomy of 14 relevant misuse classes. Through an experimental evaluation of 328 security-critical open-source Go projects, we discovered 7,473 cryptographic API misuses, providing insights into the prevalence and distribution of these vulnerabilities. Our systematic comparison reveals significant variations in misuse coverage, with immediate practical implications for security engineers and long-term implications for research in this domain.
format Preprint
id arxiv_https___arxiv_org_abs_2604_24085
institution arXiv
publishDate 2026
record_format arxiv
spellingShingle Evaluating Cryptographic API Misuse Detectors for Go
Andersson, Vivi
Monperrus, Martin
Cryptography and Security
Software Engineering
D.2.4; D.2.5
Cryptographic API misuse represents a critical vulnerability class that undermines the security foundations of modern software. Yet, it remains largely unexplored in Go despite its dominance in security-critical infrastructure. This paper presents the first comprehensive study of cryptographic API misuse detection in Go, identifying and analyzing 4 state-of-the-art tools (CodeQL, Gopher, Gosec, and Snyk Code) and establishing a consolidated taxonomy of 14 relevant misuse classes. Through an experimental evaluation of 328 security-critical open-source Go projects, we discovered 7,473 cryptographic API misuses, providing insights into the prevalence and distribution of these vulnerabilities. Our systematic comparison reveals significant variations in misuse coverage, with immediate practical implications for security engineers and long-term implications for research in this domain.
title Evaluating Cryptographic API Misuse Detectors for Go
topic Cryptography and Security
Software Engineering
D.2.4; D.2.5
url https://arxiv.org/abs/2604.24085