Skip to content
Threat Feed
high advisory

Insecure TLS Certificate Validation in alexpechkarev/google-maps

The alexpechkarev/google-maps Laravel package up to version 12.16 disables TLS certificate verification, allowing on-path attackers to perform man-in-the-middle attacks to intercept API keys and tamper with traffic.

CVE search metadata

CVE search record: CVE-2026-105222. Severity: high. CVSS: 7.4. KEV: no. Product: google-maps (<= 12.16). Brief: Insecure TLS Certificate Validation in alexpechkarev/google-maps. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-105222-google-maps/

The alexpechkarev/google-maps Laravel package, used for interacting with Google Maps web services, contains a critical security vulnerability (CVE-2026-105222) present in all versions up to and including 12.16. The package is configured by default with 'ssl_verify_peer' set to 'FALSE', which is subsequently passed to the underlying PHP 'CURLOPT_SSL_VERIFYPEER' option. This configuration failure disables TLS certificate validation for outgoing HTTPS requests. Consequently, the package does not authenticate the identity of the Google Maps API endpoints, making it susceptible to man-in-the-middle (MitM) attacks. An attacker positioned on the network path can present a fraudulent certificate, intercept sensitive traffic, exfiltrate Google Maps API keys transmitted in the request query strings, and inject malicious data into the application's service responses.

Impact

Successful exploitation allows attackers to gain unauthorized access to Google Maps API keys and modify data returned to the application. This potentially impacts any Laravel-based environment utilizing this library for service integration. Exposure of API keys can lead to unauthorized usage, financial costs, and further exploitation of the victim's Google Cloud project.

Recommendation

  • Upgrade the 'alexpechkarev/google-maps' package to a version that enforces TLS certificate validation by default.
  • Audit application configuration files to identify any existing overrides that may set 'ssl_verify_peer' to 'FALSE'.
  • Inspect egress traffic from application servers to identify anomalous attempts to establish connections to the Google Maps API that deviate from expected SSL/TLS handshake patterns.

Mitigations

Upgrade alexpechkarev/google-maps to a secure version that mandates TLS validation

immediate IT Operations

CVE-2026-105222