CVE-2026-105222 The alexpechkarev/google-maps Laravel package through… — CVE Notify — TG.ME

🚨 CVE-2026-105222
The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. On-path attackers can present any certificate to intercept Google Maps web-service requests, steal the API key from the query string, and tamper with responses.

🎖@cveNotify
GitHub
GitHub - alexpechkarev/google-maps: Collection of Google Maps API Web Services for Laravel
Collection of Google Maps API Web Services for Laravel - alexpechkarev/google-maps
October 4, 2026 42 1