PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-105222 alexpechkarev CVE debrief

The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default. This vulnerability allows on-path attackers to intercept Google Maps web-service requests, potentially leading to the theft of API keys and tampering with responses. The vulnerability arises from the bundled configuration setting ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. Defenders should prioritize verifying the use of this package and ensuring proper TLS certificate verification is enabled to prevent potential security risks.

Vendor
alexpechkarev
Product
google-maps
CVSS
CRITICAL 9.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-10-04
Original CVE updated
2026-10-04
Advisory published
2026-10-04
Advisory updated
2026-10-04

Who should care

Defenders responsible for Laravel applications using the alexpechkarev/google-maps package should assess their exposure and ensure proper TLS certificate verification is enabled to prevent potential security risks.

Why it matters

The alexpechkarev/google-maps Laravel package vulnerability allows on-path attackers to intercept Google Maps requests, potentially leading to security risks. Defenders should prioritize verifying the use of this package and ensuring proper TLS certificate verification is enabled.

  • Potential theft of API keys from Google Maps web-service requests.
  • Possible tampering with responses from Google Maps web-service requests.
  • Need to verify the use of the alexpechkarev/google-maps package and ensure proper TLS certificate verification is enabled.
  • Requirement to review and update the package version to ensure the latest security patches are applied.

Technical summary

The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. This allows on-path attackers to present any certificate to intercept Google Maps web-service requests, steal the API key from the query string, and tamper with responses. The vulnerability arises from the package's configuration, and defenders should prioritize verifying the use of this package and ensuring proper TLS certificate verification is enabled.

Defensive priority

Defenders should prioritize verifying the use of this package and ensuring proper TLS certificate verification is enabled.

Recommended defensive actions

  • Verify the use of the alexpechkarev/google-maps Laravel package in your environment.
  • Ensure proper TLS certificate verification is enabled for Google Maps web-service requests.
  • Review and update the package version to ensure the latest security patches are applied.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.

Evidence notes

The CVE description and source references indicate that the alexpechkarev/google-maps package disables TLS certificate verification by default, which can lead to security risks. The package's configuration sets ssl_verify_peer to FALSE, allowing on-path attackers to present any certificate to intercept Google Maps web-service requests. Defenders should verify the use of this package, review the configuration, and ensure proper TLS certificate verification is enabled. The evidence is limited to the CVE description and source references

Sources and references

Verified primary and authoritative sources

  • CVE-2026-105222 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-105222

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-105222 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-105222

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.