{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T10:19:03Z","timestamp":1778667543646,"version":"3.51.4"},"publisher-location":"New York, NY, USA","reference-count":36,"publisher":"ACM","license":[{"start":{"date-parts":[[2026,4,12]],"date-time":"2026-04-12T00:00:00Z","timestamp":1775952000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/legalcode"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2026,4,12]]},"DOI":"10.1145\/3786165.3788440","type":"proceedings-article","created":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T09:49:18Z","timestamp":1778665758000},"page":"25-32","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["Evaluating Cryptographic API Misuse Detectors for Go"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0000-6519-625X","authenticated-orcid":false,"given":"Vivi","family":"Andersson","sequence":"first","affiliation":[{"name":"KTH Royal Institute of Technology, Stockholm, Sweden"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3505-3383","authenticated-orcid":false,"given":"Martin","family":"Monperrus","sequence":"additional","affiliation":[{"name":"KTH Royal Institute of Technology, Stockholm, Sweden"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2026,5,13]]},"reference":[{"key":"e_1_3_3_2_2_2","volume-title":"CodeQL for Go (v1.1.13)","year":"2025","unstructured":"2025. CodeQL for Go (v1.1.13)."},{"key":"e_1_3_3_2_3_2","doi-asserted-by":"publisher","unstructured":"Sharmin Afrose Ya Xiao Sazzadur Rahaman Barton\u00a0P. Miller and Danfeng Yao. 2023. Evaluation of Static Vulnerability Detection Tools With Java Cryptographic API Benchmarks. IEEE Transactions on Software Engineering 49 2 (Feb. 2023) 485\u2013497. 10.1109\/TSE.2022.3154717","DOI":"10.1109\/TSE.2022.3154717"},{"key":"e_1_3_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2009.5"},{"key":"e_1_3_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833582"},{"key":"e_1_3_3_2_6_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.31"},{"key":"e_1_3_3_2_7_2","doi-asserted-by":"publisher","unstructured":"Jinbao Chen Boyao Ding Yu Zhang Qingwei Li and Fugen Tang. 2025. An Empirical Study of Cgo Usage in Go Projects: Distribution Purposes Patterns and Critical Issues. (February 2025). SSRN:515396110.2139\/ssrn.5153961","DOI":"10.2139\/ssrn.5153961"},{"key":"e_1_3_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2024.241032"},{"key":"e_1_3_3_2_9_2","unstructured":"CISA. 2014. SSL 3.0 POODLE Attack. https:\/\/www.cisa.gov\/news-events\/alerts\/2014\/10\/17\/ssl-30-protocol-vulnerability-and-poodle-attack. Accessed: 2025-05-30."},{"key":"e_1_3_3_2_10_2","volume-title":"gosec: Go Security Checker (v2.22.4)","author":"Cojocar Cosmin","year":"2025","unstructured":"Cosmin Cojocar, Grant Murphy, and SecureGo Team. 2025. gosec: Go Security Checker (v2.22.4). https:\/\/github.com\/securego\/gosec"},{"key":"e_1_3_3_2_11_2","unstructured":"Russ Cox and Filippo Valsorda. [n. d.]. Secure Randomness in Go 1.22. https:\/\/go.dev\/blog\/chacha8rand. Accessed: 2025-05-30."},{"key":"e_1_3_3_2_12_2","doi-asserted-by":"crossref","unstructured":"Roya Ensafi Philipp Winter Abdullah Mueen and Jedidiah\u00a0R Crandall. 2015. Analyzing the Great Firewall of China over space and time. Proceedings on privacy enhancing technologies (2015).","DOI":"10.1515\/popets-2015-0005"},{"key":"e_1_3_3_2_13_2","doi-asserted-by":"publisher","DOI":"10.1145\/3674805.3695408"},{"key":"e_1_3_3_2_14_2","doi-asserted-by":"publisher","unstructured":"Miles Frantz Ya Xiao Tanmoy\u00a0Sarkar Pias Na Meng and Danfeng Yao. 2024. Methods and Benchmark for Detecting Cryptographic API Misuses in Python. IEEE Transactions on Software Engineering 50 5 (May 2024) 1118\u20131129. 10.1109\/TSE.2024.3377182","DOI":"10.1109\/TSE.2024.3377182"},{"key":"e_1_3_3_2_15_2","doi-asserted-by":"publisher","DOI":"10.1109\/ACSAC63791.2024.00088"},{"key":"e_1_3_3_2_16_2","doi-asserted-by":"publisher","unstructured":"Paul\u00a0E. Hoffman and Bruce Schneier. 2005. Attacks on Cryptographic Hashes in Internet Protocols. RFC 4270. 10.17487\/RFC4270Num Pages: 12.","DOI":"10.17487\/RFC4270"},{"key":"e_1_3_3_2_17_2","unstructured":"IETF. 2021. Deprecating TLS 1.0 and TLS 1.1. RFC 8996. https:\/\/datatracker.ietf.org\/doc\/rfc8996\/"},{"key":"e_1_3_3_2_18_2","doi-asserted-by":"crossref","unstructured":"Michael Jones John Bradley and Nat Sakimura. 2015. JSON Web Token (JWT). RFC 7519. https:\/\/datatracker.ietf.org\/doc\/html\/rfc7519.","DOI":"10.17487\/RFC7519"},{"key":"e_1_3_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/ASE.2017.8115707"},{"key":"e_1_3_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1145\/3564625.3567989"},{"key":"e_1_3_3_2_21_2","unstructured":"Zohaib Masood and Miguel\u00a0Vargas Martin. 2024. Beyond Static Tools: Evaluating Large Language Models for Cryptographic Misuse Detection. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2411.09772 (2024)."},{"key":"e_1_3_3_2_22_2","unstructured":"MITRE. [n. d.]. CWE-1204: Generation of Weak Initialization Vector (IV). https:\/\/cwe.mitre.org\/data\/definitions\/1204.html. Accessed: 2025-05-30."},{"key":"e_1_3_3_2_23_2","unstructured":"Seyedehzahra Mosavi Chadni Islam Muhammad\u00a0Ali Babar Sharif Abuadbba and Kristen Moore. 2023. Detecting Misuse of Security APIs: A Systematic Review. Comput. Surveys (2023)."},{"key":"e_1_3_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1145\/2884781.2884790"},{"key":"e_1_3_3_2_25_2","unstructured":"National Institute of Standards and Technology. 2025. NVD - CVE-2025-66491. https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2025-66491. Accessed: 2026-01-25."},{"key":"e_1_3_3_2_26_2","first-page":"245","volume-title":"Fifteenth Symposium on Usable Privacy and Security (SOUPS 2019)","author":"Patnaik Nikhil","year":"2019","unstructured":"Nikhil Patnaik, Joseph Hallett, and Awais Rashid. 2019. Usability Smells: An Analysis of { Developers\u2019} Struggle With Crypto Libraries. In Fifteenth Symposium on Usable Privacy and Security (SOUPS 2019). 245\u2013257."},{"key":"e_1_3_3_2_27_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40001.2021.00010"},{"key":"e_1_3_3_2_28_2","first-page":"81","volume-title":"USENIX annual technical conference, FREENIX track","author":"Provos Niels","year":"1999","unstructured":"Niels Provos and David Mazieres. 1999. A future-adaptable password scheme.. In USENIX annual technical conference, FREENIX track, Vol.\u00a01999. 81\u201391."},{"key":"e_1_3_3_2_29_2","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3345659"},{"key":"e_1_3_3_2_30_2","volume-title":"Snyk Code for Go (v1.1297.1)","year":"2025","unstructured":"Snyk. 2025. Snyk Code for Go (v1.1297.1). https:\/\/docs.snyk.io\/supported-languages-package-managers-and-frameworks\/go"},{"key":"e_1_3_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.800-224.ipd"},{"key":"e_1_3_3_2_32_2","unstructured":"The Go Team. 2024. x\/crypto\/ssh: misuse of ServerConfig.PublicKeyCallback may cause authorization bypass. https:\/\/github.com\/golang\/go\/issues\/70779. Accessed: 2025-05-30."},{"key":"e_1_3_3_2_33_2","doi-asserted-by":"publisher","DOI":"10.1145\/3475716.3484195"},{"key":"e_1_3_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom56396.2022.00051"},{"key":"e_1_3_3_2_35_2","unstructured":"Yifan Xia Zichen Xie Peiyu Liu Kangjie Lu Yan Liu Wenhai Wang and Shouling Ji. 2024. Exploring Automatic Cryptographic API Misuse Detection in the Era of LLMs. arXiv preprint arXiv:https:\/\/arXiv.org\/abs\/2407.16576 (2024)."},{"key":"e_1_3_3_2_36_2","doi-asserted-by":"crossref","unstructured":"Ying Zhang Md\u00a0Mahir\u00a0Asef Kabir Ya Xiao Danfeng Yao and Na Meng. 2022. Automatic detection of Java cryptographic API misuses: Are we there yet? IEEE Transactions on Software Engineering 49 1 (2022) 288\u2013303.","DOI":"10.1109\/TSE.2022.3150302"},{"key":"e_1_3_3_2_37_2","doi-asserted-by":"publisher","DOI":"10.1145\/3658644.3690276"}],"event":{"name":"SVM '26: 4th International Workshop on Software Vulnerability Management","location":"Rio de Janeiro Brazil","acronym":"SVM '26","sponsor":["SIGSOFT ACM Special Interest Group on Software Engineering"]},"container-title":["Proceedings of the 2026 IEEE\/ACM 4th International Workshop on Software Vulnerability Management"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3786165.3788440","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2026,5,13]],"date-time":"2026-05-13T09:50:03Z","timestamp":1778665803000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3786165.3788440"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2026,4,12]]},"references-count":36,"alternative-id":["10.1145\/3786165.3788440","10.1145\/3786165"],"URL":"https:\/\/doi.org\/10.1145\/3786165.3788440","relation":{},"subject":[],"published":{"date-parts":[[2026,4,12]]},"assertion":[{"value":"2026-05-13","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}