Medium severity5.3NVD Advisory· Published Oct 4, 2026· Updated Oct 4, 2026
CVE-2026-105127
CVE-2026-105127
Description
LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS lookups and paid AbstractAPI verification calls. Unauthenticated attackers can submit arbitrary addresses to exhaust the verification quota, making validation fail open for all public forms, and probe domain resolution.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <1.4.8
Patches
Vulnerability mechanics
References
10- github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Requests/Auth/ForgotPasswordRequest.phpnvd
- github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Requests/Auth/ResetPasswordRequest.phpnvd
- github.com/laradashboard/laradashboard/blob/v1.4.2/app/Services/EmailDomainCheckService.phpnvd
- github.com/laradashboard/laradashboard/blob/v1.4.2/app/Services/EmailVerificationService.phpnvd
- github.com/laradashboard/laradashboard/commit/8babc803066a74c628fa012928fb1e6591411ebanvd
- github.com/laradashboard/laradashboard/pull/339nvd
- github.com/laradashboard/laradashboard/releases/tag/v1.4.8nvd
- github.com/laradashboard/laradashboard/security/advisories/GHSA-5hq2-r2f3-9vp9nvd
- github.com/laradashboard/laradashboard/security/advisories/GHSA-v36p-8578-8gchnvd
- www.vulncheck.com/advisories/laradashboard-1.4.2-before-1.4.8-resource-exhaustion-via-password-recovery-endpointsnvd
News mentions
0No linked articles in our index yet.