github.com/go-chi/chi/v5
Go5 known CVEs affecting this package
Aggregated from OSV, GitHub Security Advisories, NVD, and vendor advisories. Each CVE links to its full detail page with vendor advisories, patches, fixed versions, and remediation guidance.
CVEs affecting github.com/go-chi/chi/v5page 1 of 1
- CVE-2025-69725MEDIUMCVSS 4.7EG 4.7✓ Fixed in 5.2.42026-02-19
An Open Redirect vulnerability in the go-chi/chi >=5.2.2 RedirectSlashes function allows remote attackers to redirect victim users to malicious websites using the legitimate website domain.
- CVE-2025-71405MEDIUMCVSS 5.1EG 5.1✓ Fixed in 5.2.22026-08-14
chi versions before v5.2.2 contain an open redirect vulnerability in the RedirectSlashes middleware function that uses the Host header to construct redirect URLs. Attackers can manipulate the Host header to redirect users to arbitrary host…
- CVE-2026-72815MEDIUMCVSS 6.9EG 6.9✓ Fixed in 5.3.02026-08-14
go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing vulnerability in the RealIP middleware, which blindly trusts the first (leftmost) value of the X-Forwarded-For HTTP header. A remote attacker can bypass IP-based access c…
- CVE-2026-72816MEDIUMCVSS 6.5EG 6.5✓ Fixed in 5.3.02026-08-14
go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The realIP() function reads client-controlled headers (True-Client-IP, X-Real-IP, and X-Forwarded-For) and overwrites r.RemoteA…
- CVE-2026-72817MEDIUMCVSS 6.5EG 6.5✓ Fixed in 5.3.02026-08-14
go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnerability in the RealIP middleware, which resolves the request source IP (Request.RemoteAddr) using the first IP in the X-Forwarded-For header without validating trusted pr…
Check whether github.com/go-chi/chi/v5 is used in your infrastructure
EchelonGraph scans your cloud and SBOMs to map every package to your actual deployments. See blast radius for github.com/go-chi/chi/v5 CVEs against the assets you own.
Start Free Scan →