PT-2026-71987 · Github · Chi

·

CVE-2026-72817

·

Published

2026-06-25

·

Updated

2026-09-03

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions go-chi/chi versions 0.9.0 through 5.2.9
Description The RealIP middleware resolves the request source IP (Request.RemoteAddr) by using the first IP address found in the X-Forwarded-For header without validating trusted proxies. This allows a malicious client to prepend a forged IP address as the first value of the X-Forwarded-For header to spoof the request source IP, which may lead to the bypass of access controls or the falsification of request logs.
Recommendations Update go-chi/chi to version 5.3.0 or later.

Exploit

Fix

Insufficient Verification of Data Authenticity

Origin Validation Error

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

AZL-96692
CVE-2026-72817
GHSA-9G5Q-2W5X-HMXF
GO-2026-5775
OPENSUSE-SU-2026:11574-1
OPENSUSE-SU-2026:11578-1
OPENSUSE-SU-2026:11591-1
OPENSUSE-SU-2026:21645-1
OPENSUSE-SU-2026:21653-1
OPENSUSE-SU-2026:21670-1
OPENSUSE-SU-2026:21793-1
RHSA-2026:49718
RHSA-2026:49732

Affected Products

Chi