Skip to content
Open
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
Original file line number Diff line number Diff line change
Expand Up @@ -6,18 +6,32 @@
"aliases": [
"CVE-2026-105222"
],
"details": "The alexpechkarev/google-maps Laravel package through 12.16 disables TLS certificate verification by default because the bundled config sets ssl_verify_peer to FALSE, which is passed to CURLOPT_SSL_VERIFYPEER. On-path attackers can present any certificate to intercept Google Maps web-service requests, steal the API key from the query string, and tamper with responses.",
"summary": "alexpechkarev/google-maps disables TLS certificate verification by default",
"details": "The `alexpechkarev/google-maps` Laravel package disables TLS certificate and hostname verification by default starting in version 1.0.2.\n\nThe bundled configuration sets `ssl_verify_peer` to `FALSE`. This value is loaded by `WebService` and passed directly to `CURLOPT_SSL_VERIFYPEER`. When disabled, the package also sets `CURLOPT_SSL_VERIFYHOST` to `0`.\n\nAs a result, HTTPS connections made by the package do not authenticate the remote TLS endpoint by default. An on-path attacker may therefore be able to intercept or modify Google Maps web-service requests and responses, including potentially exposing API keys transmitted in request URLs.\n\nThe insecure default was introduced in commit `7f9dcce` and is present in release 1.0.2. Version 1.0.1 does not contain the `ssl_verify_peer` configuration option. The insecure default remains present in the latest release, 12.16, and on the current default branch. No patched release has been identified.",

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Confirmed after checking the upstream Git history and affected release tags.

Although ssl_verify_peer => FALSE was added to the bundled configuration in version 1.0.2, that version does not contain the WebService runtime logic that consumes this setting.

The relevant cURL behavior was introduced by commit d1867b2. The first release containing that commit is 1.0.3.

Direct tag verification shows:

  • 1.0.1: no relevant WebService SSL verification code
  • 1.0.2: no relevant WebService SSL verification code
  • 1.0.3: reads googlemaps.ssl_verify_peer into $verifySSL and passes it to CURLOPT_SSL_VERIFYPEER

Therefore, I agree that the affected range should begin at 1.0.3, not 1.0.2.

Versions through v12.16 remain affected because the bundled configuration continues to set ssl_verify_peer => FALSE. No patched release has been identified.

"severity": [
{
"type": "CVSS_V3",
"score": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N"
},
{
"type": "CVSS_V4",
"score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X"
"score": "CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N"
Comment on lines 12 to +14

Copy link
Copy Markdown
Author

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Confirmed against the pre-PR advisory metadata from the current upstream main branch.

The existing advisory contains the following CVSS v3.1 vector:

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N

The improvement was intended only to normalize the CVSS v4 vector by removing the unsupported optional X metrics. It should not remove the existing CVSS v3.1 severity metadata.

Therefore, the advisory should retain both:

  • CVSS v3.1: CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
  • CVSS v4: CVSS:4.0/AV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N

I agree that the existing CVSS v3.1 entry should be restored.

}
],
"affected": [
{
"package": {
"ecosystem": "Packagist",
"name": "alexpechkarev/google-maps"
},
"ranges": [
{
"type": "ECOSYSTEM",
"events": [
{
"introduced": "1.0.2"
}
]
}
]
}
],
"affected": [],
"references": [
{
"type": "ADVISORY",
Expand All @@ -29,12 +43,20 @@
},
{
"type": "WEB",
"url": "https://github.com/alexpechkarev/google-maps/commit/7f9dcce"
},
{
"type": "PACKAGE",
"url": "https://github.com/alexpechkarev/google-maps"
},
{
"type": "WEB",
"url": "https://github.com/alexpechkarev/google-maps/blob/v12.14/src/WebService.php#L267-L269"
},
{
"type": "WEB",
"url": "https://github.com/alexpechkarev/google-maps/blob/v12.16/src/WebService.php#L280-L281"
},
{
"type": "WEB",
"url": "https://github.com/alexpechkarev/google-maps/blob/v12.16/src/config/googlemaps.php#L28"
Expand Down
Loading