CVE-2026-105222
Received Received - Intake

Google Maps API Key Exposure via TLS Verification Bypass in Laravel Package

Vulnerability report for CVE-2026-105222, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-04

Last updated on: 2026-10-04

Assigner: VulnCheck

Description

The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. On-path attackers can present any certificate to intercept Google Maps web-service requests, steal the API key from the query string, and tamper with responses.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-04
Last Modified
2026-10-04
Generated
2026-10-05
AI Q&A
2026-10-05
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
alexpechkarev google-maps *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-295 The product does not validate, or incorrectly validates, a certificate.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is in the alexpechkarev/google-maps Laravel package version 12.16 or earlier. By default, it disables TLS certificate verification by setting ssl_verify_peer to FALSE. This allows attackers to intercept Google Maps API requests, steal the API key from the URL, and alter responses.

Detection Guidance

Check Laravel applications using the alexpechkarev/google-maps package version 12.16 or lower. Inspect configuration files for ssl_verify_peer set to FALSE. Monitor network traffic for unencrypted Google Maps API requests or suspicious API key exposure in query strings.

Impact Analysis

Attackers can intercept sensitive data sent to Google Maps services, steal your API key for potential misuse, and manipulate responses to provide false information. This could lead to data breaches or unauthorized access to your application's functionality.

Compliance Impact

This vulnerability could violate GDPR by exposing personal data during transmission and failing to ensure secure data transfer. For HIPAA, it may compromise protected health information integrity and confidentiality due to lack of encrypted verification.

Mitigation Strategies

Update the package to the latest version where ssl_verify_peer is enabled by default. Set ssl_verify_peer to TRUE in the package configuration. Rotate any exposed Google Maps API keys immediately. Ensure all requests use HTTPS and validate server certificates.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-105222. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart