A vulnerability marked as problematic has been reported in CodeIgniter up to 4.7.3. This affects the function IncomingRequest::isSecure. This manipulation causes information disclosure.

This vulnerability is tracked as CVE-2026-63220. The attack is possible to be carried out remotely. No exploit exists.

It is suggested to upgrade the affected component.