THREATOPS
THREAT OPSThreat News › [GHSA] GHSA-7wmf-pw8j-mc78 (medium) — CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure()

[GHSA] GHSA-7wmf-pw8j-mc78 (medium) — CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure()

medgithub_advisoriesPublished 2026-08-07

GHSA-7wmf-pw8j-mc78 Severity: medium CVE: CVE-2026-63220

CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure()

### Impact `IncomingRequest::isSecure()` trusted the `X-Forwarded-Proto` and `Front-End-Https` headers from any incoming request. In affected deployments, an attacker could spoof these headers and cause the application to incorrectly treat an HTTP request as secu

Indicators of compromise

Original source: https://github.com/advisories/GHSA-7wmf-pw8j-mc78