Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 14 Aug 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Go-chi
Go-chi chi |
|
| Vendors & Products |
Go-chi
Go-chi chi |
Fri, 14 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header. A remote attacker can bypass IP-based access control lists and rate-limiting mechanisms, and forge log entries, by supplying a spoofed IP address in the X-Forwarded-For header. The issue is fixed in version 5.3.0. | |
| Title | go-chi chi v5.2.1 IP Spoofing via X-Forwarded-For Header | |
| Weaknesses | CWE-290 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-14T11:35:27.496Z
Reserved: 2026-08-10T15:12:16.754Z
Link: CVE-2026-72815
No data.
Status : Received
Published: 2026-08-14T12:16:44.507
Modified: 2026-08-14T12:16:44.507
Link: CVE-2026-72815
No data.
OpenCVE Enrichment
Updated: 2026-08-14T12:45:17Z