Standard Library

GoEncodingGob

encoding/gob package. Decoder.Decode() deserializes arbitrary Go types — unsafe deserialization sink when decoding untrusted data.

1 sink
Taint flow0 sources 1 sink
Sinks — dangerous call
.Decode()

Sinks

.Decode()Sink
#
Signature
Decode(e any) error

Deserializes gob-encoded data. Unsafe deserialization sink when decoding user-controlled data.

tracks:0

Fully-Qualified Names

FQNField
encoding/gobfqns[0]

Wrong FQN → 0 findings. Verify with: change fqns to garbage → must produce 0 results.

Import

go.mod
// standard library — no go.mod entry required
rule.py
from codepathfinder.go_rule import GoEncodingGob