PatchSiren cyber security CVE debrief
CVE-2026-105222 alexpechkarev CVE debrief
The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default. This vulnerability allows on-path attackers to intercept Google Maps web-service requests, potentially leading to the theft of API keys and tampering with responses. The vulnerability arises from the bundled configuration setting ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. Defenders should prioritize verifying the use of this package and ensuring proper TLS certificate verification is enabled to prevent potential security risks.
- Vendor
- alexpechkarev
- Product
- google-maps
- CVSS
- CRITICAL 9.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-10-04
- Original CVE updated
- 2026-10-04
- Advisory published
- 2026-10-04
- Advisory updated
- 2026-10-04
Who should care
Defenders responsible for Laravel applications using the alexpechkarev/google-maps package should assess their exposure and ensure proper TLS certificate verification is enabled to prevent potential security risks.
Why it matters
The alexpechkarev/google-maps Laravel package vulnerability allows on-path attackers to intercept Google Maps requests, potentially leading to security risks. Defenders should prioritize verifying the use of this package and ensuring proper TLS certificate verification is enabled.
- Potential theft of API keys from Google Maps web-service requests.
- Possible tampering with responses from Google Maps web-service requests.
- Need to verify the use of the alexpechkarev/google-maps package and ensure proper TLS certificate verification is enabled.
- Requirement to review and update the package version to ensure the latest security patches are applied.
Technical summary
The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. This allows on-path attackers to present any certificate to intercept Google Maps web-service requests, steal the API key from the query string, and tamper with responses. The vulnerability arises from the package's configuration, and defenders should prioritize verifying the use of this package and ensuring proper TLS certificate verification is enabled.
Defensive priority
Defenders should prioritize verifying the use of this package and ensuring proper TLS certificate verification is enabled.
Recommended defensive actions
- Verify the use of the alexpechkarev/google-maps Laravel package in your environment.
- Ensure proper TLS certificate verification is enabled for Google Maps web-service requests.
- Review and update the package version to ensure the latest security patches are applied.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
- Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
Evidence notes
The CVE description and source references indicate that the alexpechkarev/google-maps package disables TLS certificate verification by default, which can lead to security risks. The package's configuration sets ssl_verify_peer to FALSE, allowing on-path attackers to present any certificate to intercept Google Maps web-service requests. Defenders should verify the use of this package, review the configuration, and ensure proper TLS certificate verification is enabled. The evidence is limited to the CVE description and source references
Sources and references
Verified primary and authoritative sources
-
CVE-2026-105222 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-105222
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-105222 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105222
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/alexpechkarev/google-maps
-
Source reference
Unverified legacy reference
URL: https://github.com/alexpechkarev/google-maps/blob/v12.14/src/WebService.php
-
Source reference
Unverified legacy reference
URL: https://github.com/alexpechkarev/google-maps/blob/v12.16/src/config/googlemaps.php
-
Source reference
Unverified legacy reference
URL: https://github.com/alexpechkarev/google-maps/issues/123
-
Source reference
Unverified legacy reference
URL: https://www.vulncheck.com/advisories/alexpechkarev-google-maps-through-12.16-disabled-tls-certificate-verification-via-ssl-verify-peer
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.