The realIP function trusts X-Real-IP and X-Forwarded-For headers from any client, not just trusted reverse proxies. This is used for:
Request logging (informational)
Rate limiting (security-critical)
An attacker can bypass the login rate limiter by sending a spoofed X-Forwarded-For header with a different IP on each request, getting unlimited login attempts.
Suggested Fix
Add a configuration option for trusted proxy CIDRs
Only trust forwarded headers when the direct connection comes from a trusted proxy
Fall back to RemoteAddr for untrusted connections
Alternatively, use chi's built-in middleware.RealIP which can be configured with trusted proxies, or always rate-limit on RemoteAddr in addition to the extracted IP.
## Severity: MEDIUM
## File: `internal/middleware/middleware.go` lines ~105-125 (realIP function)
## Description
The `realIP` function trusts `X-Real-IP` and `X-Forwarded-For` headers from any client, not just trusted reverse proxies. This is used for:
1. Request logging (informational)
2. **Rate limiting** (security-critical)
An attacker can bypass the login rate limiter by sending a spoofed `X-Forwarded-For` header with a different IP on each request, getting unlimited login attempts.
## Suggested Fix
1. Add a configuration option for trusted proxy CIDRs
2. Only trust forwarded headers when the direct connection comes from a trusted proxy
3. Fall back to `RemoteAddr` for untrusted connections
Alternatively, use chi's built-in `middleware.RealIP` which can be configured with trusted proxies, or always rate-limit on `RemoteAddr` in addition to the extracted IP.
assume any request from an RFC1918 IP is a trusted proxy. if the request has an x-real-ip or x-forwarded-for and isn't coming from an rfc1918 ip, fail closed.
assume any request from an RFC1918 IP is a trusted proxy. if the request has an x-real-ip or x-forwarded-for and isn't coming from an rfc1918 ip, fail closed.
Blocking a user prevents them from interacting with repositories, such as opening or commenting on pull requests or issues. Learn more about blocking a user.
Severity: MEDIUM
File:
internal/middleware/middleware.golines ~105-125 (realIP function)Description
The
realIPfunction trustsX-Real-IPandX-Forwarded-Forheaders from any client, not just trusted reverse proxies. This is used for:An attacker can bypass the login rate limiter by sending a spoofed
X-Forwarded-Forheader with a different IP on each request, getting unlimited login attempts.Suggested Fix
RemoteAddrfor untrusted connectionsAlternatively, use chi's built-in
middleware.RealIPwhich can be configured with trusted proxies, or always rate-limit onRemoteAddrin addition to the extracted IP.assume any request from an RFC1918 IP is a trusted proxy. if the request has an x-real-ip or x-forwarded-for and isn't coming from an rfc1918 ip, fail closed.