rpm package
opensuse/cloudflared&distro=openSUSE Leap 16.0
pkg:rpm/opensuse/cloudflared&distro=openSUSE%20Leap%2016.0
Vulnerabilities (3)
| CVE | Sev | CVSS | KEV | Affected versions | Fixed in | Published | Description |
|---|---|---|---|---|---|---|---|
| CVE-2026-72817 | Med | 6.5 | < 2026.8.2-bp160.1.1 | 2026.8.2-bp160.1.1 | Aug 14, 2026 | go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header without validating trusted proxies. A malicious client can prepend a f | |
| CVE-2026-72816 | Med | 6.5 | < 2026.8.2-bp160.1.1 | 2026.8.2-bp160.1.1 | Aug 14, 2026 | go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The realIP() function reads client-controlled headers (True-Client-IP, X-Real-IP, and X-Forwarded-For) and overwrites r.RemoteAddr without verifying that the request or | |
| CVE-2026-72815 | Med | — | < 2026.8.2-bp160.1.1 | 2026.8.2-bp160.1.1 | Aug 14, 2026 | go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header. A remote attacker can bypass IP-based access control lists and rate-limiting mechanisms |
- affected < 2026.8.2-bp160.1.1fixed 2026.8.2-bp160.1.1
go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header without validating trusted proxies. A malicious client can prepend a f
- affected < 2026.8.2-bp160.1.1fixed 2026.8.2-bp160.1.1
go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The realIP() function reads client-controlled headers (True-Client-IP, X-Real-IP, and X-Forwarded-For) and overwrites r.RemoteAddr without verifying that the request or
- affected < 2026.8.2-bp160.1.1fixed 2026.8.2-bp160.1.1
go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header. A remote attacker can bypass IP-based access control lists and rate-limiting mechanisms