PT-2026-71985 · Go Chi · Go-Chi

·

CVE-2026-72815

·

Published

2026-06-25

·

Updated

2026-09-03

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions go-chi chi versions 5.2.1 through 5.2.9
Description The RealIP middleware blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header. This allows a remote attacker to supply a spoofed IP address in the X-Forwarded-For header to bypass rate-limiting mechanisms and IP-based access control lists, as well as to forge log entries.
Recommendations Update go-chi chi to version 5.3.0.

Exploit

Fix

Insufficient Verification of Data Authenticity

Authentication Bypass by Spoofing

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72815
GHSA-3FXJ-6JH8-HVHX
GO-2026-5774
OPENSUSE-SU-2026:11607-1
OPENSUSE-SU-2026:21645-1
OPENSUSE-SU-2026:21653-1
OPENSUSE-SU-2026:21670-1
OPENSUSE-SU-2026:21793-1
RHSA-2026:49718
RHSA-2026:49732
RHSA-2026:50287
RHSA-2026:54420

Affected Products

Go-Chi