CVE-2026-105127 LaraDashboard 1.4.2 before 1.4.8 applies advanced… — CVE Notify — TG.ME

🚨 CVE-2026-105127
LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS lookups and paid AbstractAPI verification calls. Unauthenticated attackers can submit arbitrary addresses to exhaust the verification quota, making validation fail open for all public forms, and probe domain resolution.

🎖@cveNotify
GitHub
GitHub - laradashboard/laradashboard: ⚡ Lara Dashboard - CMS by Laravel - All In One solution to start your Laravel Application…
⚡ Lara Dashboard - CMS by Laravel - All In One solution to start your Laravel Application from Basic to Enterprise. Manages Users, Roles, Permissions, Modules, Settings, Translations, Contents, Mon...
October 4, 2026 30