{"id":"CVE-2026-105222","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-105222","summary":"The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed…","details":"The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. On-path attackers can present any certificate to intercept Google Maps web-service requests, steal the API key from the query string, and tamper with responses.","published":"2026-10-04T23:16:59.917","modified":"2026-10-04T23:16:59.917","cvss":{"score":7.4,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://github.com/alexpechkarev/google-maps"},{"type":"WEB","url":"https://github.com/alexpechkarev/google-maps/blob/v12.14/src/WebService.php#L267-L269"},{"type":"WEB","url":"https://github.com/alexpechkarev/google-maps/blob/v12.16/src/config/googlemaps.php#L28"},{"type":"WEB","url":"https://github.com/alexpechkarev/google-maps/issues/123"},{"type":"WEB","url":"https://www.vulncheck.com/advisories/alexpechkarev-google-maps-through-12.16-disabled-tls-certificate-verification-via-ssl-verify-peer"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-10-04T23:16:59.917"}}