GO-2026-5774None▾ SunlitChi has an IP spoofing vulnerability in middleware.RealIP in github.com/go-chi/chi
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
Chi has an IP spoofing vulnerability in middleware.RealIP in github.com/go-chi/chi
github.com/go-chi/chi/v5 >= 5.2.1, < 5.3.0Upgrade to a patched release:
github.com/go-chi/chi/v5 5.3.0Connected by shared product, vendor, weakness, or advisory.
GO-2026-5777NoneChi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header in github.com/go-chi/chi
GO-2026-5775NoneChi Middleware vulnerable to IP spoofing via X-Forwarded-For header in github.com/go-chi/chi
CVE-2025-71405Mediumchi Allows Host Header Injection which Leads to Open Redirect in RedirectSlashes
CVE-2026-72815Mediumchi Has an IP Spoofing Vulnerability in `middleware.RealIP`
CVE-2025-69725Medium· 4.7chi has an open redirect vulnerability in the RedirectSlashes middleware
GHSA-3fxj-6jh8-hvhxMediumchi Has an IP Spoofing Vulnerability in `middleware.RealIP`