Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Fri, 14 Aug 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Go-chi
Go-chi chi |
|
| Vendors & Products |
Go-chi
Go-chi chi |
Fri, 14 Aug 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header without validating trusted proxies. A malicious client can prepend a forged IP as the first value of the X-Forwarded-For header to spoof the request source IP, potentially bypassing access controls or falsifying request logs. | |
| Title | go-chi chi 0.9.0 before 5.3.0 IP Spoofing via X-Forwarded-For | |
| Weaknesses | CWE-345 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-14T11:35:28.824Z
Reserved: 2026-08-10T15:12:16.754Z
Link: CVE-2026-72817
No data.
Status : Received
Published: 2026-08-14T12:16:44.747
Modified: 2026-08-14T12:16:44.747
Link: CVE-2026-72817
No data.
OpenCVE Enrichment
Updated: 2026-08-14T13:00:11Z