What is CVE-2026-72815?
CVE-2026-72815 is an IP spoofing vulnerability in the RealIP middleware of go-chi chi versions >= 5.2.1 and before 5.3.0. Since the middleware blindly trusts the first value in the `X-Forwarded-For` header, a remote attacker can bypass IP-based access controls, rate-limiting, and forge log entries. Upgrading to version 5.3.0 or later is recommended to mitigate the issue.
Azərbaycanca: CVE-2026-72815, go-chi chi kitabxanasının 5.2.1 ilə 5.3.0 arası versiyalarında RealIP middleware-də IP spoofing zəifliyidir. Bu middleware `X-Forwarded-For` başlığının ilk dəyərinə kor-koranə inandığı üçün uzaqdan hücum edən şəxs IP əsaslı giriş nəzarətini, rate-limiting mexanizmlərini keçə və log qeydlərini saxtalaşdıra bilər. Zəiflikdən qorunmaq üçün kitabxananı 5.3.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
FAQ2
Which versions of the go-chi chi library are affected by CVE-2026-72815?
This vulnerability affects go-chi chi library versions 5.2.1 and above, but before 5.3.0.
How can one protect against CVE-2026-72815?
To mitigate the vulnerability, it is recommended to upgrade the go-chi chi library to version 5.3.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.