What is CVE-2026-72817?
CVE-2026-72817 is an IP spoofing vulnerability in the RealIP middleware of go-chi/chi versions 0.9.0 before 5.3.0, where the request source IP is resolved using the first IP in the X-Forwarded-For header without validating trusted proxies. A malicious client can prepend a forged IP, affecting systems relying on accurate IP logging or access control; users should upgrade to version 5.3.0 or later immediately.
Azərbaycanca: CVE-2026-72817, go-chi/chi kitabxanasının 0.9.0-dan 5.3.0-a qədər versiyalarında RealIP middleware-də IP spoofing zəifliyidir, burada etibarlı proxy yoxlanılmadan X-Forwarded-For başlığındakı ilk IP istifadə olunur. Bu, uzaqdan hücumçuya saxta IP ünvanı yönləndirməklə mənbə IP-ni manipulyasiya etməyə imkan verir, təsirlənən tətbiqlər üçün versiyanı dərhal 5.3.0 və ya yuxarı yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-20
FAQ2
Which versions of the go-chi/chi library are affected by CVE-2026-72817?
This vulnerability affects go-chi/chi versions 0.9.0 before 5.3.0.
What version should users upgrade to in order to mitigate CVE-2026-72817?
Users should upgrade to version 5.3.0 or later immediately.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.