CVE-2026-105222: Alexpechkarev Google-Maps

High severity, CVSS 7.4. EPSS: 0.2% chance of exploitation in the next 30 days.

The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. On-path attackers can present any certificate to intercept Google Maps web-service requests, steal the API key from the query string, and tamper with responses.

Affected products

Published 2026-10-04. Last modified 2026-10-06.