<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:alexpechkarev:google-Maps:*:*:*:*:*:*:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3aalexpechkarevgoogle-maps/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 05 Oct 2026 03:43:34 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3aalexpechkarevgoogle-maps/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Insecure TLS Certificate Validation in alexpechkarev/google-maps</title><link>https://feed.craftedsignal.io/briefs/2026-10-cve-2026-105222-google-maps/</link><pubDate>Mon, 05 Oct 2026 03:43:34 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cve-2026-105222-google-maps/</guid><description>The alexpechkarev/google-maps Laravel package up to version 12.16 disables TLS certificate verification, allowing on-path attackers to perform man-in-the-middle attacks to intercept API keys and tamper with traffic.</description><content:encoded><![CDATA[<p>The alexpechkarev/google-maps Laravel package, used for interacting with Google Maps web services, contains a critical security vulnerability (CVE-2026-105222) present in all versions up to and including 12.16. The package is configured by default with 'ssl_verify_peer' set to 'FALSE', which is subsequently passed to the underlying PHP 'CURLOPT_SSL_VERIFYPEER' option. This configuration failure disables TLS certificate validation for outgoing HTTPS requests. Consequently, the package does not authenticate the identity of the Google Maps API endpoints, making it susceptible to man-in-the-middle (MitM) attacks. An attacker positioned on the network path can present a fraudulent certificate, intercept sensitive traffic, exfiltrate Google Maps API keys transmitted in the request query strings, and inject malicious data into the application's service responses.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows attackers to gain unauthorized access to Google Maps API keys and modify data returned to the application. This potentially impacts any Laravel-based environment utilizing this library for service integration. Exposure of API keys can lead to unauthorized usage, financial costs, and further exploitation of the victim's Google Cloud project.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the 'alexpechkarev/google-maps' package to a version that enforces TLS certificate validation by default.</li>
<li>Audit application configuration files to identify any existing overrides that may set 'ssl_verify_peer' to 'FALSE'.</li>
<li>Inspect egress traffic from application servers to identify anomalous attempts to establish connections to the Google Maps API that deviate from expected SSL/TLS handshake patterns.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>supply-chain</category><category>vulnerability</category><category>laravel</category><category>mitm</category></item></channel></rss>