GHSA-mpgp-p4pg-fp7cCriticalCVSS 7.4
The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification...
🔗 CVE IDs covered (1)
📋 Description
The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. On-path attackers can present any certificate to intercept Google Maps web-service requests, steal the API key from the query string, and tamper with responses.
🔗 References (7)
- https://nvd.nist.gov/vuln/detail/CVE-2026-105222
- https://github.com/alexpechkarev/google-maps/issues/123
- https://github.com/alexpechkarev/google-maps
- https://github.com/alexpechkarev/google-maps/blob/v12.14/src/WebService.php#L267-L269
- https://github.com/alexpechkarev/google-maps/blob/v12.16/src/config/googlemaps.php#L28
- https://www.vulncheck.com/advisories/alexpechkarev-google-maps-through-12.16-disabled-tls-certificate-verification-via-ssl-verify-peer
- https://github.com/advisories/GHSA-mpgp-p4pg-fp7c