Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-72815

Опубликовано: 14 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header. A remote attacker can bypass IP-based access control lists and rate-limiting mechanisms, and forge log entries, by supplying a spoofed IP address in the X-Forwarded-For header. The issue is fixed in version 5.3.0.

A flaw was found in the go-chi chi RealIP middleware. This vulnerability allows a remote attacker to spoof their IP address by manipulating the X-Forwarded-For HTTP header. By exploiting this, an attacker can bypass IP-based access control lists and rate-limiting mechanisms, and forge log entries, potentially leading to unauthorized access or misattribution of actions.

Отчет

An IP spoofing flaw exists in go-chi/chi's RealIP middleware. When parsing incoming HTTP requests, the middleware blindly trusts the leftmost IP address in the X-Forwarded-For header without verifying proxy chain trust. Remote unauthenticated attackers can supply arbitrary client IP addresses to bypass IP-based access control lists (ACLs), evade rate-limiting rules, or forge audit trail logs, posing a Low impact to confidentiality and integrity.

Меры по смягчению последствий

Do not rely on the RealIP middleware when accepting connections from untrusted networks. Instead, configure an upstream reverse proxy (such as NGINX or HAProxy) to overwrite or sanitize client-supplied X-Forwarded-For headers before forwarding traffic to the application.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4cryostat/cryostat-storage-rhel9Fix deferred
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/bitwarden-sdk-server-rhel9Fix deferred
Gatekeeper 3gatekeeper/gatekeeper-rhel9Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/opa-openshift-rhel9Not affected
Migration Toolkit for Applications 8mta/mta-hub-rhel9Fix deferred
Multicluster Engine for Kubernetesmulticluster-engine/assisted-image-service-rhel8Not affected
Multicluster Engine for Kubernetesmulticluster-engine/assisted-image-service-rhel9Not affected
OpenShift Pipelinesopenshift-pipelines-clientFix deferred
OpenShift Pipelinesopenshift-pipelines/pipelines-opc-rhel9Fix deferred
OpenShift Serverlessopenshift-serverless-1/kn-plugin-event-sender-rhel9Not affected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-940
https://bugzilla.redhat.com/show_bug.cgi?id=2515988github.com/go-chi/chi/middleware: go-chi chi: IP spoofing via X-Forwarded-For header allows bypass of access controls

EPSS

Процентиль: 33%
0.00397
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

ubuntu
15 дней назад

go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header. A remote attacker can bypass IP-based access control lists and rate-limiting mechanisms, and forge log entries, by supplying a spoofed IP address in the X-Forwarded-For header. The issue is fixed in version 5.3.0.

nvd
15 дней назад

go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header. A remote attacker can bypass IP-based access control lists and rate-limiting mechanisms, and forge log entries, by supplying a spoofed IP address in the X-Forwarded-For header. The issue is fixed in version 5.3.0.

debian
15 дней назад

go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing v ...

github
15 дней назад

go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header. A remote attacker can bypass IP-based access control lists and rate-limiting mechanisms, and forge log entries, by supplying a spoofed IP address in the X-Forwarded-For header. The issue is fixed in version 5.3.0.

EPSS

Процентиль: 33%
0.00397
Низкий

6.5 Medium

CVSS3