GO-2026-5775None▾ SunlitChi Middleware vulnerable to IP spoofing via X-Forwarded-For header in github.com/go-chi/chi
▾ Sunlit zone — Low / medium · no exploitation signal
impact 2.8 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
Chi Middleware vulnerable to IP spoofing via X-Forwarded-For header in github.com/go-chi/chi
github.com/go-chi/chi/v5 < 5.3.0Upgrade to a patched release:
github.com/go-chi/chi/v5 5.3.0Connected by shared product, vendor, weakness, or advisory.
GO-2026-5777NoneChi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header in github.com/go-chi/chi
CVE-2026-72817Medium· 6.5go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header without validating trusted …
GO-2026-5774NoneChi has an IP spoofing vulnerability in middleware.RealIP in github.com/go-chi/chi
GHSA-9g5q-2w5x-hmxfHighchi Middleware Vulnerable to Potential IP Spoofing via `X-Forwarded-For` Header in `Request.RemoteAddr` Resolution
CVE-2025-71405Mediumchi Allows Host Header Injection which Leads to Open Redirect in RedirectSlashes
CVE-2026-72816Medium· 6.5go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go)