CVE-2026-63220Medium· 4.8▾ SunlitCodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-Forwarded-Proto and Front-End-Https headers from any incoming request, allowing an attacker could spoof these headers an…
▾ Sunlit zone — Low / medium · no exploitation signal
impact 26.4 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Aug 7.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
0.1%
Last analysed / modified upstream
CodeIgniter is a PHP full-stack web framework. In versions prior to 4.7.4, IncomingRequest::isSecure() trusted the X-Forwarded-Proto and Front-End-Https headers from any incoming request, allowing an attacker could spoof these headers and cause the application to incorrectly treat an HTTP request as secure. This may have impacted applications that rely on isSecure(), force_https(), forceGlobalSecureRequests, or similar logic to enforce HTTPS-only access or make security-sensitive decisions. Exploitability depends on deployment configuration. Applications are most exposed if the backend is reachable directly over HTTP, or if a reverse proxy/load balancer forwards client-supplied forwarding headers without stripping or overwriting them. This issue has been fixed in version 4.7.4.
Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
Affected packages:
codeigniter4/framework < 4.7.4Patched in:
codeigniter4/framework 4.7.4Connected by shared product, vendor, weakness, or advisory.
CVE-2026-63221Critical· 9.4CodeIgniter is a PHP full-stack web framework
CVE-2026-63222High· 7.5CodeIgniter is a PHP full-stack web framework
CVE-2026-48062Critical· 9.8CodeIgniter4 has a validation bypass when uploading file extensions via `ext_in` rule
CVE-2026-92530Medium· 4.3GitLab has remediated an issue in GitLab CE/EE affecting all versions from 19.1 before 19.2.7, 19.3 before 19.3.3, and 19.4 before 19.4.1 that under certain conditions could have allowed an authenticated user to spoof merge request autho…
CVE-2026-84718Medium· 4.3A flaw was found in the Ansible Automation Platform automation-controller
CVE-2026-87070Medium· 5.3The Forminator Forms WordPress plugin before 1.57.2.1 does not verify that a request came from a trusted proxy before preferring client-supplied forwarding headers over the connecting address, and it uses that value both to enforce its p…