Medium severity6.5NVD Advisory· Published Aug 14, 2026
CVE-2026-72817
CVE-2026-72817
Description
go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header without validating trusted proxies. A malicious client can prepend a forged IP as the first value of the X-Forwarded-For header to spoof the request source IP, potentially bypassing access controls or falsifying request logs.
Affected products
1Patches
Vulnerability mechanics
References
2News mentions
0No linked articles in our index yet.