CVE-2026-105222
CRITICAL
9,1
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Confidentiality: N/A
Integrity: N/A
Availability: N/A
HIGH
7,4
Source: [email protected]
Attack Vector: network
Attack Complexity: high
Privileges Required: none
User Interaction: none
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: none
Description
AI Translation Available
The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. On-path attackers can present any certificate to intercept Google Maps web-service requests, steal the API key from the query string, and tamper with responses.
295
Improper Certificate Validation
DraftCommon Consequences
Security Scopes Affected:
Integrity
Authentication
Potential Impacts:
Bypass Protection Mechanism
Gain Privileges Or Assume Identity
Applicable Platforms
Technologies:
Not Technology-Specific, Web Based, Mobile
https://github.com/alexpechkarev/google-maps
https://github.com/alexpechkarev/google-maps/blob/v12.14/src/WebService.php#L26…
https://github.com/alexpechkarev/google-maps/blob/v12.16/src/config/googlemaps.…
https://github.com/alexpechkarev/google-maps/issues/123
https://www.vulncheck.com/advisories/alexpechkarev-google-maps-through-12.16-di…