Import Source
https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-96689.json
JSON Data
https://api.osv.dev/v1/vulns/AZL-96689
Upstream
Published
2026-08-14T12:16:44Z
Modified
2026-08-31T05:26:27Z
Summary
CVE-2026-72816 affecting package influxdb 2.7.5-19
Details

go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the RealIP middleware (middleware/realip.go). The realIP() function reads client-controlled headers (True-Client-IP, X-Real-IP, and X-Forwarded-For) and overwrites r.RemoteAddr without verifying that the request originated from a trusted proxy. Attackers can supply arbitrary IP addresses in these headers to bypass IP-based access controls, evade rate limiting and geo-IP restrictions, and pollute audit logs. Fixed in 5.3.0.

References

Affected packages

Azure Linux:3 / influxdb

Package

Name
influxdb
Purl
pkg:rpm/azure-linux/influxdb

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.7.5-19

Database specific

source
"https://github.com/microsoft/AzureLinuxVulnerabilityData/blob/main/osv/AZL-96689.json"