Security Flaw in Google Maps Laravel Package by Alex Pechkarev
CVE-2026-105222

9.1CRITICAL

Key Information:

Vendor
CVE Published:
4 October 2026

What is CVE-2026-105222?

The Google Maps Laravel package by Alex Pechkarev, up to version 12.16, has a significant vulnerability where it disables TLS certificate verification by default. This is due to the configuration setting of ssl_verify_peer being set to FALSE. This flaw permits on-path attackers to generate fraudulent certificates, enabling them to intercept web service requests to Google Maps. They can not only extract sensitive information like API keys from the query string but also manipulate the responses being transmitted. Proper security measures should be implemented to ensure the integrity and confidentiality of the API interactions.

Affected Version(s)

google-maps 1.0.3 <= 12.16

References

CVSS V4

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Siyang Wu
.