VulnSea

go-chi has 11 CVEs on record between 2025 and 2026. Disclosure cadence is accelerating: 9 in the last 90 days against 0 in the 90 before. The busiest recent month was June 2026 with 4. The median CVSS is 6.5 (medium). None have a confirmed exploitation report. The most common weakness class is CWE-290 (3). Most affected products: github.com/go-chi/chi/v5 (5), github.com/go-chi/chi/middleware (4), github.com/go-chi/chi/v5/middleware (2).

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
6.5
Publish → KEV
Last 90 days
9 prev 0

Products

  • github.com/go-chi/chi/v5 5
  • github.com/go-chi/chi/middleware 4
  • github.com/go-chi/chi/v5/middleware 2
11
Total CVEs
0
Critical
0
CISA KEV
0
Exploited

go-chi vulnerabilities

CVEs affecting go-chi, newest first. Open any entry for full detail, references, and exploit status.

11 CVEsRSS

CVE-2026-72816Medium· 6.5
1mo ago

go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go)

go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The realIP() function reads client-controlled headers (True-Client-IP, X-Real-IP, and X-Forwarded-For) and overwrites r.Remot…

Sunlitgo-chi · github.com/go-chi/chi/middlewareEPSS 0.22%via NVD
CVE-2026-72817Medium· 6.5
1mo ago

go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header without validating trusted …

go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header without validating trusted …

Sunlitgo-chi · github.com/go-chi/chi/middlewareEPSS 0.15%via NVD
GO-2026-5777None
2mo ago

Chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header in github.com/go-chi/chi

Chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header in github.com/go-chi/chi

Sunlitgo-chi · github.com/go-chi/chi/v5via OSV
GO-2026-5775None
2mo ago

Chi Middleware vulnerable to IP spoofing via X-Forwarded-For header in github.com/go-chi/chi

Chi Middleware vulnerable to IP spoofing via X-Forwarded-For header in github.com/go-chi/chi

Sunlitgo-chi · github.com/go-chi/chi/v5via OSV
GO-2026-5774None
2mo ago

Chi has an IP spoofing vulnerability in middleware.RealIP in github.com/go-chi/chi

Chi has an IP spoofing vulnerability in middleware.RealIP in github.com/go-chi/chi

Sunlitgo-chi · github.com/go-chi/chi/v5via OSV
CVE-2026-72815MediumPoC
2mo ago

chi Has an IP Spoofing Vulnerability in `middleware.RealIP`

chi Has an IP Spoofing Vulnerability in `middleware.RealIP`

Twilightgo-chi · github.com/go-chi/chi/v5/middlewareEPSS 0.40%via OSV
GHSA-rjr7-jggh-pgcpHigh
2mo ago

chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header

chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header

Twilightgo-chi · github.com/go-chi/chi/middlewarevia GHSA
GHSA-9g5q-2w5x-hmxfHigh
2mo ago

chi Middleware Vulnerable to Potential IP Spoofing via `X-Forwarded-For` Header in `Request.RemoteAddr` Resolution

chi Middleware Vulnerable to Potential IP Spoofing via `X-Forwarded-For` Header in `Request.RemoteAddr` Resolution

Twilightgo-chi · github.com/go-chi/chi/middlewarevia GHSA
GHSA-3fxj-6jh8-hvhxMedium
2mo ago

chi Has an IP Spoofing Vulnerability in `middleware.RealIP`

chi Has an IP Spoofing Vulnerability in `middleware.RealIP`

Sunlitgo-chi · github.com/go-chi/chi/v5/middlewarevia GHSA
CVE-2025-69725Medium· 4.7
8mo ago

chi has an open redirect vulnerability in the RedirectSlashes middleware

chi has an open redirect vulnerability in the RedirectSlashes middleware

Sunlitgo-chi · github.com/go-chi/chi/v5EPSS 0.22%via OSV
CVE-2025-71405Medium
1y ago

chi Allows Host Header Injection which Leads to Open Redirect in RedirectSlashes

chi Allows Host Header Injection which Leads to Open Redirect in RedirectSlashes

Sunlitgo-chi · github.com/go-chi/chi/v5EPSS 0.31%via OSV
go-chi vulnerabilities (CVEs) · VulnSea