Skip to main content
EPSS 0.5%top 60%

Security update for cloudflared

0
High
Published: 08/27/2026 (08/27/2026, 19:43:09 UTC)
Source: GCVE Database
Vendor/Project: SUSE Product Security Team
Product: SUSE

Description

This update for cloudflared fixes the following issues: Changes in cloudflared: - Update version to 2026.8.2 * Update vendor archive to fix github.com/go-chi/chi/v5 (boo#1276196, CVE-2026-72815, CVE-2026-72816, CVE-2026-72817) * Add OpenRC support * Migrate config renovate.json * Fix bugs

Affected software

Affected versions
=1.14.7-0.4.hum1SUSEaarch64cloudflared-2026.8.2-bp160.1.1.aarch64ppc64lecloudflared-2026.8.2-bp160.1.1.ppc64le

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/11/2026, 04:47:46 UTC

Technical Analysis

Red Hat has released an update for Hardened Images RPMs including spire1.14 packages (version 1.14.7-0.4.hum1) that fix multiple vulnerabilities such as CVE-2026-72815, CVE-2026-72816, and CVE-2026-72817. A key vulnerability (CVE-2026-72816) involves the go-chi/chi RealIP middleware, which improperly trusts unvalidated HTTP headers (True-Client-IP, X-Real-IP, X-Forwarded-For) to overwrite the remote address, enabling IP spoofing. This can allow attackers to bypass IP-restricted endpoints, evade rate limits, and poison audit logs. The vulnerability has a medium impact rating and no known exploits in the wild. The Red Hat advisory recommends not using the RealIP middleware directly with untrusted networks and instead sanitizing headers at upstream proxies. The update packages are available for aarch64 and x86_64 architectures.

Potential Impact

The IP spoofing vulnerability in the go-chi/chi RealIP middleware allows remote unauthenticated attackers to supply arbitrary IP addresses in HTTP headers, potentially bypassing IP-based access controls, evading rate limiting and geo-IP restrictions, and polluting audit logs. This poses a low impact to confidentiality and integrity but can undermine access control mechanisms and logging accuracy. The overall severity is medium as assessed by Red Hat. There are no known exploits in the wild at this time.

Mitigation Recommendations

Red Hat has released updated RPM packages (spire1.14 version 1.14.7-0.4.hum1) that fix the vulnerabilities described. Users should apply these updates to remediate the issues. Additionally, for the IP spoofing vulnerability in the RealIP middleware, Red Hat advises not to use this middleware when receiving traffic directly from untrusted networks or unverified proxies. Instead, client-supplied forwarding headers should be stripped or sanitized at an upstream edge proxy or reverse proxy (e.g., NGINX or HAProxy) before requests reach the application. Follow the vendor advisory instructions for applying updates and mitigation.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Gcve Source
db.gcve.eu
Csaf Category
csaf_security_advisory
Csaf Version
2.0
Publisher
Red Hat Product Security
Advisory Id
RHSA-2026:49718
Cve Count
3
Additional Cves
["CVE-2026-72816","CVE-2026-72817"]
State
PUBLISHED

Threat ID: 6a870a50acd9273b49b58584

Added to database: 08/20/2026, 14:08:16 UTC

Last enriched: 09/11/2026, 04:47:46 UTC

Last updated: 10/05/2026, 06:48:18 UTC

Views: 45

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses