Sceawere

Vulnerability Detail

CVE-2026-105222UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Insecure TLS Verification in alexpechkarev/google-maps

Vulnerability Metadata

Severity
High
Score / CVSS
7.4
Creation Date
19h ago
Vendor
alexpechkarev
Product
google-maps
Attack Type
Improper Certificate Validation
Vector String
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Attack Complexity
HIGH

Narrative and Response

Description

The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. On-path attackers can present any certificate to intercept Google Maps web-service requests, steal the API key from the query string, and tamper with responses.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.4",
  "pubDate": "2026-10-04T23:16:59.917Z",
  "pubdate": "2026-10-04T23:16:59.917Z",
  "executiveSummary": "The alexpechkarev/google-maps Laravel package, in versions up to and including 12.16, contains a critical security misconfiguration involving the disabling of TLS certificate validation. By setting the 'ssl_verify_peer' configuration option to FALSE, the library explicitly instructs the underlying transport mechanism to ignore the identity of the remote server during HTTPS communication.\nThis vulnerability classifies as an Improper Certificate Validation issue, which fundamentally undermines the trust model of the TLS protocol. An on-path attacker, such as a malicious actor performing a man-in-the-middle (MitM) attack, can intercept outgoing requests destined for the Google Maps web services. Because the package fails to verify the authenticity of the presented SSL/TLS certificate, the attacker can present a fraudulent certificate and successfully intercept or tamper with sensitive traffic.\nThe primary risk implications include the exfiltration of the Google Maps API key, which is transmitted as a query string parameter, and the manipulation of API responses. Exploitation requires the attacker to be positioned on the network path between the application server and Google's infrastructure. Given that no authentication or specialized privileges are required to initiate such an interception, this represents a significant threat to data confidentiality and integrity for all applications utilizing this package.",
  "technicalDetails": "The root cause of this vulnerability lies in the default configuration settings of the alexpechkarev/google-maps package. The library utilizes PHP's cURL extension for HTTP communication. Within the package's configuration files, the 'ssl_verify_peer' setting is explicitly defined as FALSE. This value is subsequently mapped to the CURLOPT_SSL_VERIFYPEER constant during the initialization of the cURL handle.\nWhen CURLOPT_SSL_VERIFYPEER is set to FALSE, the cURL library disables the peer verification process. During the TLS handshake, the client (the Laravel application) fails to perform any cryptographic validation of the server's X.509 certificate chain. Consequently, the client does not verify that the server's certificate is signed by a trusted Certificate Authority (CA), nor does it confirm that the certificate matches the hostname being contacted.\nThe attack flow proceeds as follows: 1) The Laravel application initiates a request to the Google Maps API. 2) An on-path attacker intercepting network traffic intercepts this request. 3) The attacker presents an arbitrary, self-signed, or otherwise invalid TLS certificate to the client application. 4) Because the package has disabled peer verification, the application treats the attacker's certificate as valid and establishes an encrypted tunnel directly to the attacker rather than the legitimate Google Maps server. 5) The attacker then acts as a transparent proxy, decrypting, logging, and potentially modifying the traffic.\nThis vulnerability is particularly severe because the Google Maps API key, which is required for authentication with Google's services, is typically passed as a plaintext parameter within the URL query string. By decrypting the TLS traffic, an attacker can easily extract this API key, allowing them to perform unauthorized API calls, exhaust quota limits, or conduct further reconnaissance on the victim's infrastructure. Furthermore, because the attacker controls the connection, they can perform response tampering, injecting malicious data or breaking application functionality by modifying the JSON responses returned by the Google Maps API.\nThis issue affects all versions of the package up to 12.16. The vulnerability is inherently present in the architectural design of the network client implementation and is not mitigated by server-side authentication, as the failure occurs at the client-side transport layer."
}
CVE-2026-105222: Insecure TLS Verification in alexpechkarev/google-maps (HIGH Severity, CVSS: 7.4) | Sceawere