The ideal solution below should be: img-src 'self' information:image/svg+xml. If it doesn't do the job test: img-src 'self' info:Look at altering it if you still have your directive as img-src * 'self' data: https:; Chrome, Opera, and Edge have a safe term You may use to bypass this SSL issue https://fireratedductworkinductio67889.blogscribble.com/37667981/the-smart-trick-of-accessory-boxes-that-nobody-is-discussing