VYPR
Medium severity5.3NVD Advisory· Published Oct 4, 2026· Updated Oct 4, 2026

CVE-2026-105127

CVE-2026-105127

Description

LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS lookups and paid AbstractAPI verification calls. Unauthenticated attackers can submit arbitrary addresses to exhaust the verification quota, making validation fail open for all public forms, and probe domain resolution.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

1

Patches

Vulnerability mechanics

References

10

News mentions

0

No linked articles in our index yet.