VulnSea

github.com/go-chi/chi/middleware vulnerabilities

CVEs whose affected-version data names the github.com/go-chi/chi/middleware package (go). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

4 CVEsRSS

CVE-2026-72816Medium· 6.5
1mo ago

go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go)

go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The realIP() function reads client-controlled headers (True-Client-IP, X-Real-IP, and X-Forwarded-For) and overwrites r.Remot…

▾ Sunlitgo-chi · github.com/go-chi/chi/middlewareEPSS 0.30%via NVD
CVE-2026-72817Medium· 6.5
1mo ago

go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header without validating trusted …

go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header without validating trusted …

▾ Sunlitgo-chi · github.com/go-chi/chi/middlewareEPSS 0.24%via NVD
GHSA-rjr7-jggh-pgcpHigh
3mo ago

chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header

chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header

▾ Twilightgo-chi · github.com/go-chi/chi/middlewarevia GHSA
GHSA-9g5q-2w5x-hmxfHigh
3mo ago

chi Middleware Vulnerable to Potential IP Spoofing via `X-Forwarded-For` Header in `Request.RemoteAddr` Resolution

chi Middleware Vulnerable to Potential IP Spoofing via `X-Forwarded-For` Header in `Request.RemoteAddr` Resolution

▾ Twilightgo-chi · github.com/go-chi/chi/middlewarevia GHSA
github.com/go-chi/chi/middleware vulnerabilities (CVEs) · VulnSea