PT-2026-104656 · Alexpechkarev · Google Maps

·

CVE-2026-105222

·

Published

2026-10-04

·

Updated

2026-10-04

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl verify peer to FALSE, which is passed to CURLOPT SSL VERIFYPEER. On-path attackers can present any certificate to intercept Google Maps web-service requests, steal the API key from the query string, and tamper with responses.

Fix

Improper Certificate Validation

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-105222

Affected Products

Google Maps