{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/google-maps--12.16/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:alexpechkarev:google-maps:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-105222"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["google-maps (\u003c= 12.16)"],"_cs_severities":["high"],"_cs_tags":["supply-chain","vulnerability","laravel","mitm"],"_cs_type":"advisory","_cs_vendors":["alexpechkarev"],"content_html":"\u003cp\u003eThe alexpechkarev/google-maps Laravel package, used for interacting with Google Maps web services, contains a critical security vulnerability (CVE-2026-105222) present in all versions up to and including 12.16. The package is configured by default with 'ssl_verify_peer' set to 'FALSE', which is subsequently passed to the underlying PHP 'CURLOPT_SSL_VERIFYPEER' option. This configuration failure disables TLS certificate validation for outgoing HTTPS requests. Consequently, the package does not authenticate the identity of the Google Maps API endpoints, making it susceptible to man-in-the-middle (MitM) attacks. An attacker positioned on the network path can present a fraudulent certificate, intercept sensitive traffic, exfiltrate Google Maps API keys transmitted in the request query strings, and inject malicious data into the application's service responses.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to gain unauthorized access to Google Maps API keys and modify data returned to the application. This potentially impacts any Laravel-based environment utilizing this library for service integration. Exposure of API keys can lead to unauthorized usage, financial costs, and further exploitation of the victim's Google Cloud project.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the 'alexpechkarev/google-maps' package to a version that enforces TLS certificate validation by default.\u003c/li\u003e\n\u003cli\u003eAudit application configuration files to identify any existing overrides that may set 'ssl_verify_peer' to 'FALSE'.\u003c/li\u003e\n\u003cli\u003eInspect egress traffic from application servers to identify anomalous attempts to establish connections to the Google Maps API that deviate from expected SSL/TLS handshake patterns.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-05T03:43:34Z","date_published":"2026-10-05T03:43:34Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-105222-google-maps/","summary":"The alexpechkarev/google-maps Laravel package up to version 12.16 disables TLS certificate verification, allowing on-path attackers to perform man-in-the-middle attacks to intercept API keys and tamper with traffic.","title":"Insecure TLS Certificate Validation in alexpechkarev/google-maps","url":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-105222-google-maps/"}],"language":"en","title":"CraftedSignal Threat Feed - Google-Maps (\u003c= 12.16)","version":"https://jsonfeed.org/version/1.1"}