High severity7.4NVD Advisory· Published Oct 4, 2026
CVE-2026-105222
CVE-2026-105222
Description
The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. On-path attackers can present any certificate to intercept Google Maps web-service requests, steal the API key from the query string, and tamper with responses.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=12.16
Patches
Vulnerability mechanics
References
4- github.com/alexpechkarev/google-maps/blob/v12.14/src/WebService.phpnvd
- github.com/alexpechkarev/google-maps/blob/v12.16/src/config/googlemaps.phpnvd
- github.com/alexpechkarev/google-maps/issues/123nvd
- www.vulncheck.com/advisories/alexpechkarev-google-maps-through-12.16-disabled-tls-certificate-verification-via-ssl-verify-peernvd
News mentions
0No linked articles in our index yet.