Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-72817

Опубликовано: 14 авг. 2026
Источник: redhat
CVSS3: 6.5
EPSS Низкий

Описание

go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header without validating trusted proxies. A malicious client can prepend a forged IP as the first value of the X-Forwarded-For header to spoof the request source IP, potentially bypassing access controls or falsifying request logs.

A flaw was found in the go-chi/chi component. The RealIP middleware, responsible for resolving the request source IP, does not properly validate trusted proxies when processing the X-Forwarded-For header. A remote attacker can exploit this by prepending a forged IP address to the X-Forwarded-For header, leading to IP spoofing. This could allow the attacker to bypass access controls or falsify request logs.

Отчет

A flaw in the go-chi/chi RealIP middleware allows remote attackers to spoof source IP addresses (Request.RemoteAddr). The middleware parses the first IP address in the X-Forwarded-For header without verifying if the immediate HTTP proxy peer is trusted. An unauthenticated attacker can prepend an arbitrary IP address to the X-Forwarded-For header, causing applications relying on RealIP for request context to misidentify the client source. This enables bypassing application-level IP-based access control lists (ACLs) or spoofing identity in audit logs.

Меры по смягчению последствий

Disable the default RealIP middleware and replace it with a proxy-aware middleware (such as httputil.ReverseProxy or custom header parsing) that strictly validates upstream reverse proxies against an explicit list of trusted CIDR ranges before accepting X-Forwarded-For headers.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Cryostat 4cryostat/cryostat-storage-rhel9Fix deferred
External Secrets Operator for Red Hat OpenShiftexternal-secrets-operator/bitwarden-sdk-server-rhel9Fix deferred
Gatekeeper 3gatekeeper/gatekeeper-rhel9Fix deferred
Logging Subsystem for Red Hat OpenShiftopenshift-logging/opa-openshift-rhel9Fix deferred
Migration Toolkit for Applications 8mta/mta-hub-rhel9Fix deferred
Multicluster Engine for Kubernetesmulticluster-engine/assisted-image-service-rhel8Fix deferred
Multicluster Engine for Kubernetesmulticluster-engine/assisted-image-service-rhel9Fix deferred
OpenShift Pipelinesopenshift-pipelines-clientFix deferred
OpenShift Pipelinesopenshift-pipelines/pipelines-opc-rhel9Fix deferred
OpenShift Serverlessopenshift-serverless-1/kn-plugin-event-sender-rhel9Fix deferred

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-501
https://bugzilla.redhat.com/show_bug.cgi?id=2516008github.com/go-chi/chi/middleware: go-chi/chi: IP spoofing via X-Forwarded-For header manipulation

EPSS

Процентиль: 4%
0.0015
Низкий

6.5 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.5
ubuntu
15 дней назад

go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header without validating trusted proxies. A malicious client can prepend a forged IP as the first value of the X-Forwarded-For header to spoof the request source IP, potentially bypassing access controls or falsifying request logs.

CVSS3: 6.5
nvd
15 дней назад

go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header without validating trusted proxies. A malicious client can prepend a forged IP as the first value of the X-Forwarded-For header to spoof the request source IP, potentially bypassing access controls or falsifying request logs.

CVSS3: 6.5
msrc
6 дней назад

go-chi chi 0.9.0 before 5.3.0 IP Spoofing via X-Forwarded-For

CVSS3: 6.5
debian
15 дней назад

go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnera ...

CVSS3: 6.5
github
15 дней назад

go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header without validating trusted proxies. A malicious client can prepend a forged IP as the first value of the X-Forwarded-For header to spoof the request source IP, potentially bypassing access controls or falsifying request logs.

EPSS

Процентиль: 4%
0.0015
Низкий

6.5 Medium

CVSS3