CVE-2026-105127
Deferred Deferred - Pending Action

LaraDashboard Password Reset DNS Exhaustion Flaw

Vulnerability report for CVE-2026-105127, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-04

Last updated on: 2026-10-04

Assigner: VulnCheck

Description

LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS lookups and paid AbstractAPI verification calls. Unauthenticated attackers can submit arbitrary addresses to exhaust the verification quota, making validation fail open for all public forms, and probe domain resolution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-04
Last Modified
2026-10-04
Generated
2026-10-04
AI Q&A
2026-10-04
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
laradashboard laradashboard to 1.4.8 (exc)
laradashboard laradashboard From 1.4.2 (inc) to 1.4.8 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-770 The product allocates a reusable resource or group of resources on behalf of an actor without imposing any intended restrictions on the size or number of resources that can be allocated.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-105127 is a vulnerability in LaraDashboard versions 1.4.2 to 1.4.7 where unauthenticated password recovery endpoints perform excessive email validation including DNS lookups and paid AbstractAPI verification calls. Attackers can exploit this by submitting arbitrary email addresses to exhaust verification quotas, causing validation to fail open and bypass security controls. The system also performs slow DNS lookups for attacker-controlled domains, acting as a reconnaissance tool.

Detection Guidance

Monitor for excessive DNS lookups or AbstractAPI verification calls from the /password/email endpoint. Check for HTTP 302 responses (valid domains) or 422 errors (invalid/blocked domains) indicating DNS oracle behavior. Review logs for failed password recovery attempts due to domain restrictions.

Impact Analysis

This vulnerability allows attackers to deny service to legitimate users by exhausting verification quotas, lock out admins with internal-domain emails, and probe domain resolution via DNS oracle attacks. It can also consume server resources through slow DNS lookups, leading to degraded performance or crashes. Organizations using affected versions may face disrupted password recovery, unauthorized access attempts, and increased operational costs from paid API usage.

Compliance Impact

This vulnerability could violate GDPR's availability principle by disrupting password recovery for users, and HIPAA's access control requirements if it leads to unauthorized access. The fail-open behavior may compromise data integrity by bypassing email verification controls. Organizations must ensure proper remediation to maintain compliance with security and privacy standards.

Mitigation Strategies

Upgrade to LaraDashboard 1.4.8 or later. Disable EmailSubmissionValidator for password recovery routes. Implement rate limiting on /password/email endpoints. Remove unnecessary AbstractAPI calls for unauthenticated requests. Enable fail-closed behavior with admin alerts after quota exhaustion.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105127. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart