Skip to content
VulniPulse
Advisory severityMedium6.5Red Hat Linux

Medium [CVE-2026-72817] IP spoofing via X-Forwarded-For header manipulation

This medium-severity Red Hat Linux advisory covers CVE-2026-72817 affecting Red Hat Hardened Images, Cryostat 4, External Secrets Operator for Red Hat OpenShift.

Aggregated and source-linked by VulniPulse. Data sources, validation and limitations.

CVE-2026-72817 Source published Source updated

VulniPulse record published Record updated

Affected products & platforms
Red Hat LinuxRed Hat Enterprise Linux
Open source advisory

Android app · Google Play

Monitor future Red Hat Linux CVEs from your phone.

Choose a whole vendor or a precise platform, then receive matching security advisories by phone notification, email, or both. Coverage follows 32 official vendor sources and 160+ reviewed platform categories.

Matching phone alertsOptional email delivery

Summary

go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request. RemoteAddr) using the first IP in the X-Forwarded-For header without validating trusted proxies.

A malicious client can prepend a forged IP as the first value of the X-Forwarded-For header to spoof the request source IP, potentially bypassing access controls or falsifying request logs. A flaw was found in the `go-chi/chi` component.

A remote attacker can exploit this by prepending a forged IP address to the `X-Forwarded-For` header, leading to IP spoofing. The middleware parses the first IP address in the `X-Forwarded-For` header without verifying if the immediate HTTP proxy peer is trusted.

An unauthenticated attacker can prepend an arbitrary IP address to the `X-Forwarded-For` header, causing applications relying on `RealIP` for request context to misidentify the client source. This enables bypassing application-level IP-based access control lists (ACLs) or spoofing identity in audit logs.

Red Hat severity: Moderate — CVSS 6.5 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N). Weakness: CWE-501.

Affected products named by the advisory: Red Hat Hardened Images; Cryostat 4; External Secrets Operator for Red Hat OpenShift; Gatekeeper 3; and 19 more.

Affected versions
  • < 0.9.0
  • < 5.3.0

Official advisory · high-confidence parse· fetched 18 days ago·verify at source

Fixed versions
  • spire1-14-main-1.14.7-0.4.hum1
  • spire1-15-main-1.15.2-0.4.hum1
  • cosign-main-3.1.3-0.1.hum1
  • RHSA-2026:49718
  • RHSA-2026:49732
  • RHSA-2026:54420

Official advisory · high-confidence parse· fetched 18 days ago·verify at source

Mitigation checklist

Recommended fix / mitigation
  • Disable the default `RealIP` middleware and replace it with a proxy-aware middleware (such as `httputil.ReverseProxy` or custom header parsing) that strictly validates upstream reverse proxies against an explicit list of trusted CIDR ranges before accepting `X-Forwarded-For` headers.

Official advisory · high-confidence parse· fetched 18 days ago·verify at source

Discussion(0)

No comments yet. Share field notes, upgrade gotchas, or questions — verify against the vendor advisory before acting on community advice.

Sign in to join the discussion.