Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-96635.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-96635
Upstream
Published
2026-08-14T12:16:44Z
Modified
2026-08-30T05:26:50Z
Summary
CVE-2026-72816 affecting package gh for versions less than 2.97.0-1
Details

go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The realIP() function reads client-controlled headers (True-Client-IP, X-Real-IP, and X-Forwarded-For) and overwrites r.RemoteAddr without verifying that the request originated from a trusted proxy. Attackers can supply arbitrary IP addresses in these headers to bypass IP-based access controls, evade rate limiting and geo-IP restrictions, and pollute audit logs. Fixed in 5.3.0.

References

Affected packages

Azure Linux:3 / gh

Package

Name
gh
Purl
pkg:rpm/azure-linux/gh

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
2.97.0-1

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-96635.json"