CVE-2026-72816

EUVD-2026-58631
go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The realIP() function reads client-controlled headers (True-Client-IP, X-Real-IP, and X-Forwarded-For) and overwrites r.RemoteAddr without verifying that the request originated from a trusted proxy. Attackers can supply arbitrary IP addresses in these headers to bypass IP-based access controls, evade rate limiting and geo-IP restrictions, and pollute audit logs. Fixed in 5.3.0.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
6.5 MEDIUM
NETWORK
LOW
NONE
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Awaiting analysis
This vulnerability is currently awaiting analysis.
Base Score
CVSS 3.x
EPSS Score
Percentile: 20.41%
Debian logo
Debian Releases
Debian Product
Codename
golang-github-go-chi-chi
bookworm
ignored
bullseye
ignored
forky
5.3.0-1
fixed
sid
5.3.0-1
fixed
trixie
no-dsa
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
golang-github-go-chi-chi
jammy
needs-triage
noble
needs-triage
resolute
needs-triage
Azure Linux logo
Azure Linux Releases
Azure Package
Release
gh
Azure Linux 3.0
0:2.97.0-1.azl3
fixed