THREAT OPS › Threat News › [GHSA] GHSA-7wmf-pw8j-mc78 (medium) — CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure()
[GHSA] GHSA-7wmf-pw8j-mc78 (medium) — CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure()
GHSA-7wmf-pw8j-mc78 Severity: medium CVE: CVE-2026-63220
CodeIgniter: Spoofable forwarded HTTPS headers in IncomingRequest::isSecure()
### Impact `IncomingRequest::isSecure()` trusted the `X-Forwarded-Proto` and `Front-End-Https` headers from any incoming request. In affected deployments, an attacker could spoof these headers and cause the application to incorrectly treat an HTTP request as secu
Indicators of compromise
- CVE-2026-63220cve
Original source: https://github.com/advisories/GHSA-7wmf-pw8j-mc78