CVE-2026-105222

Summary

The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. On-path attackers can present any certificate to intercept Google Maps web-service requests, steal the API key from the query string, and tamper with responses.

Affected Software

VendorProductVersion RangeStatus
alexpechkarevgoogle-maps1.0.3 <= 12.16affected

Weaknesses

  • CWE-295: Improper Certificate Validation

References