VDB
CVE-2026-72816
CVE-2026-72816
PUBLISHED
CVSS 6.9 MEDIUM
Reported by VulnCheck · Published August 14, 2026
go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The realIP() function reads client-controlled headers (True-Client-IP, X-Real-IP, and X-Forwarded-For) and overwrites r.RemoteAddr without verifying that the request originated from a trusted proxy. Attackers can supply arbitrary IP addresses in these headers to bypass IP-based access controls, evade rate limiting and geo-IP restrictions, and pollute audit logs. Fixed in 5.3.0.
Risk Scores
CVSS 4.0
6.9
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| go-chi | chi | 0, 5.3.0 |
| go-chi | chi | 0, 5.3.0, 0 |
Timeline
- Aug 14, 2026 Coalition ESS Score
- Aug 14, 2026 CVE Published
- Aug 20, 2026 Security Advisory
- Aug 24, 2026 EPSS Score
- Sep 5, 2026 EPSS Score
- Sep 12, 2026 EPSS Score
- Sep 17, 2026 EPSS Score
- Sep 18, 2026 EPSS Score
- Sep 24, 2026 EPSS Score
- Sep 26, 2026 EPSS Score
- Sep 30, 2026 EPSS Score
- Oct 2, 2026 EPSS Score
References
- GitHub Security Advisory (GHSA-rjr7-jggh-pgcp) vendor-advisory
- VulnCheck Advisory: go-chi chi before 5.3.0 IP Spoofing via RealIP Middleware third-party-advisory