---
id: CVE-2026-105127
title: >-
  LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to
  unauthenticated forgot-password and reset-password requests, triggering DNS
  lookups and paid AbstractAPI verification calls
summary: >-
  LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to
  unauthenticated forgot-password and reset-password requests, triggering DNS
  lookups and paid AbstractAPI verification calls. Unauthenticated attackers can
  submit arbit…
severity: medium
cvss: 5.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:L'
cwe:
  - CWE-770
vendor: laradashboard
product: laradashboard
affected:
  - laradashboard >= 1.4.2 < 1.4.8
published: '2026-10-04'
updated: '2026-10-04'
sourceUpdated: '2026-10-04T00:16:36.517'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105127'
references:
  - url: 'https://github.com/laradashboard/laradashboard'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Requests/Auth/ForgotPasswordRequest.php#L22-L27
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Http/Requests/Auth/ResetPasswordRequest.php#L23-L30
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Services/EmailDomainCheckService.php#L128
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/laradashboard/laradashboard/blob/v1.4.2/app/Services/EmailVerificationService.php#L95-L114
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/laradashboard/laradashboard/commit/8babc803066a74c628fa012928fb1e6591411eba
    label: disclosure@vulncheck.com
  - url: 'https://github.com/laradashboard/laradashboard/pull/339'
    label: disclosure@vulncheck.com
  - url: 'https://github.com/laradashboard/laradashboard/releases/tag/v1.4.8'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/laradashboard/laradashboard/security/advisories/GHSA-5hq2-r2f3-9vp9
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/laradashboard/laradashboard/security/advisories/GHSA-v36p-8578-8gch
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/laradashboard-1.4.2-before-1.4.8-resource-exhaustion-via-password-recovery-endpoints
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-04T00:50:56.108Z'
epss: 0.00406
epssPercentile: 0.32572
---

## Overview

LaraDashboard 1.4.2 before 1.4.8 applies advanced email validation to unauthenticated forgot-password and reset-password requests, triggering DNS lookups and paid AbstractAPI verification calls. Unauthenticated attackers can submit arbitrary addresses to exhaust the verification quota, making validation fail open for all public forms, and probe domain resolution.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
