Skip to content

.#10304

Closed
gr8man wants to merge 4 commits into
codeigniter4:developfrom
gr8man:fix/incomingrequest-issecure
Closed

.#10304
gr8man wants to merge 4 commits into
codeigniter4:developfrom
gr8man:fix/incomingrequest-issecure

Conversation

@gr8man

@gr8man gr8man commented Jun 11, 2026

Copy link
Copy Markdown
Contributor

.

@memleakd

Copy link
Copy Markdown
Contributor

@gr8man Thanks for the contribution, but please avoid disclosing potential security vulnerabilities in public PRs.

As mentioned before, CI4 security issues should be reported privately according to the Security Policy.

Could you please close this PR, remove any publicly disclosed details, and contact security@codeigniter.com instead?

@gr8man gr8man closed this Jun 11, 2026
@gr8man gr8man deleted the fix/incomingrequest-issecure branch June 11, 2026 21:57
@gr8man gr8man changed the title fix(HTTP): validate remote address against trusted proxies in isSecure() (CWE-348) . Jun 11, 2026
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants