A vulnerability in go-chi/chi versions 0.9.0 before 5.3.0 allows for IP spoofing via the X-Forwarded-For header, potentially bypassing access controls or falsifying request logs. This issue arises from the RealIP middleware resolving the request source IP using the first IP in the X-Forwarded-For header without validating trusted proxies. The vulnerability could allow malicious clients to prepend forged I [truncated]
CVE-2026-72816 is an IP spoofing vulnerability in the RealIP middleware of go-chi/chi versions up to 5.2.1. The vulnerability allows attackers to bypass IP-based access controls, evade rate limiting and geo-IP restrictions, and pollute audit logs by supplying arbitrary IP addresses in client-controlled headers. This vulnerability impacts defenders who rely on IP-based security measures, as it can lead to [truncated]
A vulnerability in go-chi chi versions >= 5.2.1 and before 5.3.0 allows for IP spoofing via the X-Forwarded-For HTTP header. This issue is fixed in version 5.3.0. The vulnerability allows a remote attacker to bypass IP-based access control lists and rate-limiting mechanisms, and forge log entries, by supplying a spoofed IP address in the X-Forwarded-For header. Defenders should assess exposure and apply t [truncated]
CVE-2025-71405 is an open redirect vulnerability in the RedirectSlashes middleware function of the chi framework versions before v5.2.2. The vulnerability uses the Host header to construct redirect URLs, allowing attackers to manipulate the Host header and redirect users to arbitrary hosts. This enables phishing attacks and credential theft. Defenders should prioritize verifying the vulnerability in their [truncated]
CVE-2025-69725 is an Open Redirect vulnerability in the go-chi/chi >=5.2.2 RedirectSlashes function. This CVE record was published on 2026-02-19T17:24:39.830Z and was last modified on 2026-07-05T02:17:37.113Z. The NVD entry is currently Deferred. The vulnerability allows remote attackers to redirect victim users to malicious websites using the legitimate website domain. Users and administrators should be [truncated]