{"id":"AZL-96635","summary":"CVE-2026-72816 affecting package gh for versions less than 2.97.0-1","details":"go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The realIP() function reads client-controlled headers (True-Client-IP, X-Real-IP, and X-Forwarded-For) and overwrites r.RemoteAddr without verifying that the request originated from a trusted proxy. Attackers can supply arbitrary IP addresses in these headers to bypass IP-based access controls, evade rate limiting and geo-IP restrictions, and pollute audit logs. Fixed in 5.3.0.","modified":"2026-08-31T05:26:27Z","published":"2026-08-14T12:16:44Z","upstream":["CVE-2026-72816"],"references":[{"type":"WEB","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72816"}],"affected":[{"package":{"name":"gh","ecosystem":"Azure Linux:3","purl":"pkg:rpm/azure-linux/gh"},"ranges":[{"type":"ECOSYSTEM","events":[{"introduced":"0"},{"fixed":"2.97.0-1"}]}],"database_specific":{"source":"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-96635.json"}}],"schema_version":"1.9.0"}