The Ctx.IsFromLocal function can incorrectly report a request as being sent from localhost when the request contains an X-Forwarded-For header containing a localhost IP address.
{
    "url": "https://pkg.go.dev/vuln/GO-2023-2052",
    "review_status": "REVIEWED"
}