Executive brief
A vulnerability in the chi web framework's RealIP middleware allows attackers to spoof their source IP address. This middleware is used to identify the original visitor's IP when a website is behind a load balancer or proxy. By manipulating network headers, an attacker can trick the system into recording a false IP, potentially bypassing security restrictions or corrupting audit logs.
Technical details
The RealIP() middleware in the chi library incorrectly resolves the client's source IP by selecting the first value in the 'X-Forwarded-For' HTTP header. Because this header is additive, an attacker can prepend a forged IP address to the header (e.g., 'X-Forwarded-For: <forged-ip>, <actual-client-ip>'). The middleware then populates 'Request.RemoteAddr' with the forged IP. This is a classic origin validation error (CWE-346) occurring because the implementation does not verify IPs from the end of the chain against a list of trusted proxies. The issue is resolved in version 5.3.0.
Affected products
- go-chi chi/middleware >= 0.9.0, <= 1.5.5
- go-chi chi/v2/middleware <= 2.1.1
- go-chi chi/v3/middleware <= 3.3.5
- go-chi chi/v4/middleware <= 4.1.3
- go-chi chi/v5/middleware < 5.3.0
Timeline
- 2026-05-22: disclosed
- 2026-06-25: advisory: GitHub Advisory published
- 2026-06-25: patched: Version 5.3.0 released